Server Connection problem
My server is under attack. when I check SYN packets with
netstat -anp | grep SYN
very much pages are coming. But server doesnt have any load problem and this server has 1 gbit port. So I have enough connection and cpu power but server is closing network connection. How can I solve this problem with kernel ?
This is Kernel error message. I have very much of this at my messages.
Feb 5 22:46:41 server kernel: Pid: 2784, comm: lshttpd
Feb 5 22:46:41 server kernel: EIP: 0060:[<c042a97a>] CPU: 2
Feb 5 22:46:41 server kernel: EIP is at local_bh_enable_ip+0xe/0x3e
Feb 5 22:46:41 server kernel: EFLAGS: 00000212 Not tainted (2.6.18-92.1.22.el5PAE #1)
Feb 5 22:46:41 server kernel: EAX: eb882000 EBX: 00020000 ECX: f7d44000 EDX: eb882000
Feb 5 22:46:41 server kernel: ESI: 00000000 EDI: 000071af EBP: f7f3c6bc DS: 007b ES: 007b
Feb 5 22:46:41 server kernel: CR0: 8005003b CR2: 081eee20 CR3: 32b7da20 CR4: 000006f0
Feb 5 22:46:41 server kernel: [<c05c47a2>] rt_garbage_collect+0x192/0x293
Feb 5 22:46:41 server kernel: [<c05b152d>] dst_alloc+0x16/0x81
Feb 5 22:46:41 server kernel: [<c05c5c55>] __ip_route_output_key+0x556/0x7f0
Feb 5 22:46:41 server kernel: [<c05c5f02>] ip_route_output_flow+0x13/0x1d8
Feb 5 22:46:41 server kernel: [<c05d03fa>] inet_csk_route_req+0xd7/0x159
Feb 5 22:46:41 server kernel: [<c052a2fd>] secure_tcp_sequence_number+0x5c/0x73
Feb 5 22:46:41 server kernel: [<c05de423>] tcp_v4_send_synack+0x17/0xe4
Feb 5 22:46:41 server kernel: [<c05e04ad>] tcp_v4_conn_request+0x39b/0x3e6
Feb 5 22:46:41 server kernel: [<c04e56f6>] memmove+0xe/0x22
Feb 5 22:46:41 server kernel: [<c05d8ba1>] tcp_rcv_state_process+0x5d/0xcc5
Feb 5 22:46:41 server kernel: [<c05df146>] tcp_v4_do_rcv+0x274/0x2bc
Feb 5 22:46:41 server kernel: [<c05a7787>] release_sock+0x44/0x91
Feb 5 22:46:41 server kernel: [<c05d0676>] inet_csk_accept+0x1e1/0x1eb
Feb 5 22:46:41 server kernel: [<c05e94fb>] inet_accept+0x1c/0xa0
Feb 5 22:46:41 server kernel: [<c05a6a08>] sys_accept+0xf6/0x1c0
Feb 5 22:46:41 server kernel: [<c04851f7>] destroy_inode+0x36/0x45
Feb 5 22:46:41 server kernel: [<c0483ef6>] dput+0x22/0xed
Feb 5 22:46:41 server kernel: [<c049e9cf>] proc_flush_task+0x97/0x1b0
Feb 5 22:46:41 server kernel: [<c040a0fb>] restore_i387+0x87/0x1a1
Feb 5 22:46:41 server kernel: [<c04043c0>] restore_sigcontext+0x15e/0x1b6
Feb 5 22:46:41 server kernel: [<c05a6b7a>] sys_socketcall+0xa8/0x19e
Feb 5 22:46:41 server kernel: [<c0407eea>] do_syscall_trace+0xab/0xb1
Feb 5 22:46:41 server kernel: [<c0404eff>] syscall_call+0x7/0xb
Feb 5 22:46:41 server kernel: =======================
Feb 5 22:46:41 server kernel: printk: 6595 messages suppressed.
Feb 5 22:46:41 server kernel: dst cache overflow
Feb 5 22:46:46 server kernel: printk: 6594 messages suppressed.
Feb 5 22:46:46 server kernel: dst cache overflow
Feb 5 22:46:51 server kernel: BUG: soft lockup - CPU#2 stuck for 10s! [lshttpd:2784]
|