SYN flood on port 80. Disconnects all agents.
Posted: Fri Jul 25, 2014 1:21 pm
Hello,
A client of mine let me know of an event that occurred today at 9:45 AM, in which all agents at a given Vicidial Server got disconnected. I checked the dmesg and found this:
[11201.121850] TCP: Possible SYN flooding on port 80. Sending cookies. Check SNMP counters.
Since the server was rebooted at 6:34 AM, after adding the 3:06 hours into the event the time frame of the problem seems to match with the log record, so I´m assuming that the 2 events are related to each other.
I checked how many connections are established at TCP port 80 by using : netstat -tuna | grep ":80" | wc -l and right now the server is throwing 13,544 results at me. There are currently 80 agents logged into this server.
As far as I know this isn´t supposed to be a Vicidial issue, but rather a Kernel one. However, if anyone else has run into this error, I´d like to know if there´s a way to solve this (without offloading the apache to another server).
Server specs: Intel(R) Xeon(R) CPU E5645 @ 2.40GHz, 12 cores, 54 GB RAM, usual load : 2.39, 2.21, 2.15. Vicibox 4.0.3 with Vicidial VERSION: 2.8-415a BUILD: 131007-1234.
Any ideas?
Regards,
A client of mine let me know of an event that occurred today at 9:45 AM, in which all agents at a given Vicidial Server got disconnected. I checked the dmesg and found this:
[11201.121850] TCP: Possible SYN flooding on port 80. Sending cookies. Check SNMP counters.
Since the server was rebooted at 6:34 AM, after adding the 3:06 hours into the event the time frame of the problem seems to match with the log record, so I´m assuming that the 2 events are related to each other.
I checked how many connections are established at TCP port 80 by using : netstat -tuna | grep ":80" | wc -l and right now the server is throwing 13,544 results at me. There are currently 80 agents logged into this server.
As far as I know this isn´t supposed to be a Vicidial issue, but rather a Kernel one. However, if anyone else has run into this error, I´d like to know if there´s a way to solve this (without offloading the apache to another server).
Server specs: Intel(R) Xeon(R) CPU E5645 @ 2.40GHz, 12 cores, 54 GB RAM, usual load : 2.39, 2.21, 2.15. Vicibox 4.0.3 with Vicidial VERSION: 2.8-415a BUILD: 131007-1234.
Any ideas?
Regards,