singlespeed
05-02-2003, 10:47 AM
I've got 2 RH8 servers running qmail as a mail relay
they're both behind a firewall and have an additional IPTABLES firewall running on them.
The mail servers are qmail, the ftp is wu-ftp (hardened, not anom login)
both are running RAV antivirus for mail servers.
server1 has qmail and ftp
server2 has just qmail
this morning some wierd stuff started happening, smtp on server2 is taking forever to acknowledge requests and ftp on server1 is doing the same thing.
Also if I ssh to either maching i get a login prompt right away but then a long delay before a password prompt. This has not historically been the case.
if I telnet to port 25 on server 2, it takes forever. If I ftp to server1, connection is right away but prompt for login takes forever.
This all just started happening this morning. Nothing strange in the logs.
Any Ideas?
Server 1
[root@mail /]# ps -ax
PID TTY STAT TIME COMMAND
1 ? S 0:06 init
2 ? SW 0:00 [keventd]
3 ? SW 0:00 [kapmd]
4 ? SWN 0:00 [ksoftirqd_CPU0]
5 ? SW 0:00 [kswapd]
6 ? SW 0:00 [bdflush]
7 ? SW 0:00 [kupdated]
8 ? SW 0:00 [mdrecoveryd]
12 ? SW 0:00 [kjournald]
88 ? SW 0:00 [khubd]
212 ? SW 0:00 [kjournald]
674 ? S 0:00 syslogd -m 0
679 ? S 0:00 klogd -2
791 ? S 0:00 /usr/sbin/apmd -p 10 -w 5 -W -P /etc/sysconfig/apm-scripts/apmscript
812 ? S 0:00 /usr/sbin/sshd
845 ? S 0:00 xinetd -stayalive -reuse -pidfile /var/run/xinetd.pid
865 ? S 0:00 ravmd: supervise RAV scanning process...
867 ? S 0:01 ravmd: accepting connections ...
900 ? S 0:00 gpm -t ps/2 -m /dev/mouse
918 ? S 0:00 crond
954 ? S 0:00 [atd]
976 ? S 0:00 rhnsd --interval 120
980 tty1 S 0:00 /sbin/mingetty tty1
981 tty2 S 0:00 /sbin/mingetty tty2
982 tty3 S 0:00 /sbin/mingetty tty3
983 tty4 S 0:00 /sbin/mingetty tty4
984 tty5 S 0:00 /sbin/mingetty tty5
985 tty6 S 0:00 /sbin/mingetty tty6
986 ? S 0:00 /bin/sh /command/svscanboot
990 ? S 0:00 svscan /service
991 ? S 0:00 readproctitle service errors: .................................................. ...............
993 ? S 0:00 supervise log
995 ? S 0:00 supervise log
996 ? S 0:00 /usr/local/bin/multilog t /var/log/qmail
997 ? S 0:00 /usr/local/bin/multilog t /var/log/qmail/smtpd
2349 ? S 0:00 /usr/sbin/sshd
2377 pts/2 S 0:00 -bash
3146 ? S 0:00 supervise qmail-smtpd
3303 ? S 0:00 supervise qmail-send
3694 ? S 0:00 [qmail-send]
3697 ? S 0:00 qmail-lspawn ./Mailbox
3698 ? S 0:00 [qmail-rspawn]
3699 ? S 0:00 [qmail-clean]
3703 ? S 0:00 [tcpserver]
4596 ? SN 0:00 in.ftpd -l -a
4614 pts/2 R 0:00 ps -ax
they're both behind a firewall and have an additional IPTABLES firewall running on them.
The mail servers are qmail, the ftp is wu-ftp (hardened, not anom login)
both are running RAV antivirus for mail servers.
server1 has qmail and ftp
server2 has just qmail
this morning some wierd stuff started happening, smtp on server2 is taking forever to acknowledge requests and ftp on server1 is doing the same thing.
Also if I ssh to either maching i get a login prompt right away but then a long delay before a password prompt. This has not historically been the case.
if I telnet to port 25 on server 2, it takes forever. If I ftp to server1, connection is right away but prompt for login takes forever.
This all just started happening this morning. Nothing strange in the logs.
Any Ideas?
Server 1
[root@mail /]# ps -ax
PID TTY STAT TIME COMMAND
1 ? S 0:06 init
2 ? SW 0:00 [keventd]
3 ? SW 0:00 [kapmd]
4 ? SWN 0:00 [ksoftirqd_CPU0]
5 ? SW 0:00 [kswapd]
6 ? SW 0:00 [bdflush]
7 ? SW 0:00 [kupdated]
8 ? SW 0:00 [mdrecoveryd]
12 ? SW 0:00 [kjournald]
88 ? SW 0:00 [khubd]
212 ? SW 0:00 [kjournald]
674 ? S 0:00 syslogd -m 0
679 ? S 0:00 klogd -2
791 ? S 0:00 /usr/sbin/apmd -p 10 -w 5 -W -P /etc/sysconfig/apm-scripts/apmscript
812 ? S 0:00 /usr/sbin/sshd
845 ? S 0:00 xinetd -stayalive -reuse -pidfile /var/run/xinetd.pid
865 ? S 0:00 ravmd: supervise RAV scanning process...
867 ? S 0:01 ravmd: accepting connections ...
900 ? S 0:00 gpm -t ps/2 -m /dev/mouse
918 ? S 0:00 crond
954 ? S 0:00 [atd]
976 ? S 0:00 rhnsd --interval 120
980 tty1 S 0:00 /sbin/mingetty tty1
981 tty2 S 0:00 /sbin/mingetty tty2
982 tty3 S 0:00 /sbin/mingetty tty3
983 tty4 S 0:00 /sbin/mingetty tty4
984 tty5 S 0:00 /sbin/mingetty tty5
985 tty6 S 0:00 /sbin/mingetty tty6
986 ? S 0:00 /bin/sh /command/svscanboot
990 ? S 0:00 svscan /service
991 ? S 0:00 readproctitle service errors: .................................................. ...............
993 ? S 0:00 supervise log
995 ? S 0:00 supervise log
996 ? S 0:00 /usr/local/bin/multilog t /var/log/qmail
997 ? S 0:00 /usr/local/bin/multilog t /var/log/qmail/smtpd
2349 ? S 0:00 /usr/sbin/sshd
2377 pts/2 S 0:00 -bash
3146 ? S 0:00 supervise qmail-smtpd
3303 ? S 0:00 supervise qmail-send
3694 ? S 0:00 [qmail-send]
3697 ? S 0:00 qmail-lspawn ./Mailbox
3698 ? S 0:00 [qmail-rspawn]
3699 ? S 0:00 [qmail-clean]
3703 ? S 0:00 [tcpserver]
4596 ? SN 0:00 in.ftpd -l -a
4614 pts/2 R 0:00 ps -ax