Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | debug checkpoint fw-1 on nokia ipso |
|---|---|
| Date: | Fri, 14 Jan 2005 22:30:33 +0100 |
Hi list
We're having severe trouble with an old installation of checkpoint's fw-1
(ver. 4.1 sp6) on nokia ipso 3.5-FCS14. ("upgrade", i hear you say. yes,
we're at it, but it will take more time than we have to solve this)
Symptoms: At random times the box gets 100% loaded, i.e.
- a constant 0% cpu idle time reported by vmstat (with 99% in system, 1% in
user mode)
- shell is almost unresponsive (charactes on prompt echoed at a rate of one
per 30 seconds, commands never returning, login taking about 10 minutes)
- box practically stops forwarding any traffic
- interface throughput drops to zero on ALL interfaces (measured in retrospect
on switch and in ipso interface statistics)
- box takes about 3 seconds to reply to icmp echo-request
- box stops sending out OSPF and VRRP packets, resulting in failovers and OSPF
recalculations, then occasionally sends one out, resulting in another session
of failovers and routing convergences.
Then, after 10-30 minutes, suddenly all returns to normal (80% idle), nothing
in the logs except for the OSPF messages from ipsrd.
On one occasion I managed to get a "ps auxw" through, and it showed monitord
using 10% cpu and fwd using 8% cpu, all other processes were using below
0.1%. But I assume this only showed userspace processes.
From all that I see, it's the kernel using all resources, or a hardware
fault.
Now: is anyone aware of a tool or method to get more information about what is
causing this load? Has anyone heard of an attack that might cause these
symptoms? Can anyone remember a bug in that version of fw-1/ipso that might
result in this behaviour? Generic observations?
I'd be grateful for any pointer.
thanks
/markus
pgpoNqF05KG8E.pgp
Description: PGP signature
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: PIX 512E as VPN server : internal users ?, Andrew Shore |
|---|---|
| Next by Date: | RE: debug checkpoint fw-1 on nokia ipso, Pablo Hauser |
| Previous by Thread: | RE: Security Information Management versus Security Network Management applications, Phil Hollows |
| Next by Thread: | RE: debug checkpoint fw-1 on nokia ipso, Pablo Hauser |
| Indexes: | [Date] [Thread] [Top] [All Lists] |