Re: tcp connection limit exceeded msgs
- From: Craig Lalley <mr_lalley@xxxxxxxxx>
- Date: Sat, 19 Aug 2006 20:21:10 -0700
Guessing out loud... did anyone have a port scanner running?
-Craig
johnpitman <johnpitman@xxxxxxxxxxxxxxx> wrote:
N series , 1 x 220Hgz cpu, 1 GB ram, 1 x 18GB, 1 x 36gb hdd MPE 7.5.02
During a normal day we have up to 220 sessions, maybe 30-50 jobs running.
95% of the sessions are network vt-mgr connections. Maybe occasions when
memory bound, but overall ok performance.
Saturday morning get a call that only one guy can log on....get on my vpn
from home. I can ping the system, and other devices on the network, but
reflections wont connect, nor will telnet......
After getting the one logged on user to log off, I can get on, and actually
open 4 sessions. Eventually I see 'tcp connection limit exceeded' msgs on
console. In nettool->status->tcpstat->tcpglobal I see that connections
currently open is sitting on configured limit.....2048
In the end I drove into work , but I couldn't see any obvious source of all
the connections. We have a pc that does ftps from system every minute, but
it was behaving normally. I stopped Jinetd job, no change. I stopped the
jdbc job, no change, or maybe a little - the current connections count
drifted down as low as 2036, but then climbed again.
I shutdown the network, restarted it, current connections went straight to
1823.....who are they?
In the end I configured the max connections up to 4096, and rebooted it.
Currently (couple of hours later), with 3 sessions, a couple of jobs, and
the occasion ftp process, connections open is 88. In the last 10mins crept
up to 98...
Any idea how one finds out who all the connectees are please? This smells a
little like the attack we had on our firewall a while ago....
TIA
jp
* To join/leave the list, search archives, change list settings, *
* etc., please visit http://raven.utc.edu/archives/hp3000-l.html *
---------------------------------
Get your email and more, right on the new Yahoo.com
* To join/leave the list, search archives, change list settings, *
* etc., please visit http://raven.utc.edu/archives/hp3000-l.html *
.
- References:
- tcp connection limit exceeded msgs
- From: johnpitman
- tcp connection limit exceeded msgs
- Prev by Date: Re: tcp connection limit exceeded msgs
- Next by Date: Re: more tcp questions
- Previous by thread: Re: tcp connection limit exceeded msgs
- Next by thread: more tcp questions
- Index(es):
Relevant Pages
|