- 论坛徽章:
- 0
|
回复 2# chenyx
在不通的时候 ,内网是 通的。
早上出现不通时,重启服务器不行,重新启用 网卡也不通了。我是刚刚才把网卡启用(时间间隔有3个小时, 上行有其它工作没有管它得),又好了。
怀疑肯定还是被攻击所致。
我看了下 iptables-save 导出的内容 与我之前预写入的内容是完全 一致的,也就是说,没有被在 iptables 上做手脚。
boot.log 中看起来没有任何问题发生,全是OK 连 warning 也没有一个。
最后一次故障后启动时的 dmesg 内容:
[ 0.000000] Initializing cgroup subsys cpuset
[ 0.000000] Initializing cgroup subsys cpu
[ 0.000000] Linux version 3.5.0-28-generic (buildd@panlong) (gcc version 4.7.2 (Ubuntu/Linaro 4.7.2-2ubuntu1) ) #48-Ubuntu SMP Tue Apr 23 23:03:38 UTC 2013 (Ubuntu 3.5.0-28.48-generic 3.5.7.9)
[ 0.000000] Command line: BOOT_IMAGE=/vmlinuz-3.5.0-28-generic root=/dev/mapper/filesvr-root ro
[ 0.000000] KERNEL supported cpus:
[ 0.000000] Intel GenuineIntel
[ 0.000000] AMD AuthenticAMD
[ 0.000000] Centaur CentaurHauls
[ 0.000000] e820: BIOS-provided physical RAM map:
[ 0.000000] BIOS-e820: [mem 0x0000000000000000-0x000000000009fbff] usable
[ 0.000000] BIOS-e820: [mem 0x000000000009fc00-0x000000000009ffff] reserved
[ 0.000000] BIOS-e820: [mem 0x00000000000e0000-0x00000000000fffff] reserved
[ 0.000000] BIOS-e820: [mem 0x0000000000100000-0x00000000bf75ffff] usable
[ 0.000000] BIOS-e820: [mem 0x00000000bf76e000-0x00000000bf76ffff] reserved
[ 0.000000] BIOS-e820: [mem 0x00000000bf770000-0x00000000bf77dfff] ACPI data
[ 0.000000] BIOS-e820: [mem 0x00000000bf77e000-0x00000000bf7cffff] ACPI NVS
[ 0.000000] BIOS-e820: [mem 0x00000000bf7d0000-0x00000000bf7dffff] reserved
[ 0.000000] BIOS-e820: [mem 0x00000000bf7ed000-0x00000000bfffffff] reserved
[ 0.000000] BIOS-e820: [mem 0x00000000e0000000-0x00000000efffffff] reserved
[ 0.000000] BIOS-e820: [mem 0x00000000fee00000-0x00000000fee00fff] reserved
[ 0.000000] BIOS-e820: [mem 0x00000000ffa00000-0x00000000ffffffff] reserved
[ 0.000000] BIOS-e820: [mem 0x0000000100000000-0x00000001bfffffff] usable
[ 0.000000] NX (Execute Disable) protection: active
[ 0.000000] SMBIOS 2.5 present.
[ 0.000000] DMI: HP ProLiant DL180 G6 , BIOS O20 10/15/2009
[ 0.000000] e820: update [mem 0x00000000-0x0000ffff] usable ==> reserved
[ 0.000000] e820: remove [mem 0x000a0000-0x000fffff] usable
"dmesg" 983L, 64977C 1,1 Top
[ 6.658936] type=1400 audit(1368493607.171:5): apparmor="STATUS" operation="profile_load" name="/usr/lib/NetworkManager/nm-dhcp-client.action" pid=534 comm="apparmor_parser"
[ 6.658943] type=1400 audit(1368493607.171:6): apparmor="STATUS" operation="profile_replace" name="/usr/lib/NetworkManager/nm-dhcp-client.action" pid=529 comm="apparmor_parser"
[ 6.658950] type=1400 audit(1368493607.171:7): apparmor="STATUS" operation="profile_replace" name="/usr/lib/NetworkManager/nm-dhcp-client.action" pid=614 comm="apparmor_parser"
[ 6.659156] type=1400 audit(1368493607.171: : apparmor="STATUS" operation="profile_load" name="/usr/lib/connman/scripts/dhclient-script" pid=534 comm="apparmor_parser"
[ 6.659165] type=1400 audit(1368493607.171:9): apparmor="STATUS" operation="profile_replace" name="/usr/lib/connman/scripts/dhclient-script" pid=529 comm="apparmor_parser"
[ 6.659172] type=1400 audit(1368493607.171:10): apparmor="STATUS" operation="profile_replace" name="/usr/lib/connman/scripts/dhclient-script" pid=614 comm="apparmor_parser"
[ 6.706095] EXT4-fs (sda1): mounted filesystem with ordered data mode. Opts: (null)
[ 6.718033] ip_tables: (C) 2000-2006 Netfilter Core Team
[ 6.725766] nf_conntrack version 0.5.0 (16384 buckets, 65536 max)
[ 6.732672] EXT4-fs (dm-0): mounted filesystem with ordered data mode. Opts: (null)
[ 6.824982] IPv6: ADDRCONF(NETDEV_UP): eth0: link is not ready
[ 6.828182] microcode: CPU1 sig=0x106a5, pf=0x1, revision=0x11
[ 6.829316] microcode: CPU2 sig=0x106a5, pf=0x1, revision=0x11
[ 6.830360] microcode: CPU3 sig=0x106a5, pf=0x1, revision=0x11
[ 6.831377] microcode: CPU4 sig=0x106a5, pf=0x1, revision=0x11
[ 6.832502] microcode: CPU5 sig=0x106a5, pf=0x1, revision=0x11
[ 6.833693] microcode: CPU6 sig=0x106a5, pf=0x1, revision=0x11
[ 6.834735] microcode: CPU7 sig=0x106a5, pf=0x1, revision=0x11
[ 6.835803] microcode: Microcode Update Driver: v2.00 <tigran@aivazian.fsnet.co.uk>, Peter Oruba
[ 6.839993] kvm: disabled by bios
[ 6.917968] kvm: disabled by bios
[ 6.937087] IPv6: ADDRCONF(NETDEV_UP): eth1: link is not ready
[ 7.019072] kvm: disabled by bios
[ 7.023003] kvm: disabled by bios
[ 7.044115] kvm: disabled by bios
[ 7.119914] kvm: disabled by bios
[ 7.123819] kvm: disabled by bios
[ 7.209237] EXT4-fs (dm-1): mounted filesystem with ordered data mode. Opts: (null)
[ 7.222919] kvm: disabled by bios
[ 7.281764] EXT4-fs (dm-2): mounted filesystem with ordered data mode. Opts: (null)
[ 7.734086] vesafb: mode is 1024x768x32, linelength=4096, pages=0
[ 7.734090] vesafb: scrolling: redraw
[ 7.734093] vesafb: Truecolor: size=8:8:8:8, shift=24:16:8:0
[ 7.738813] vesafb: framebuffer at 0xf8000000, mapped to 0xffffc90011c80000, using 3072k, total 3072k
[ 7.738992] Console: switching to colour frame buffer device 128x48
[ 7.773742] fb0: VESA VGA frame buffer device
[ 7.990149] kjournald starting. Commit interval 5 seconds
[ 7.990575] EXT3-fs (dm-3): using internal journal
[ 7.990580] EXT3-fs (dm-3): mounted filesystem with ordered data mode
[ 8.069780] init: failsafe main process (947) killed by TERM signal
[ 8.183566] type=1400 audit(1368493608.699:11): apparmor="STATUS" operation="profile_load" name="/usr/sbin/named" pid=1052 comm="apparmor_parser"
[ 8.221696] igb: eth0 NIC Link is Up 100 Mbps Full Duplex, Flow Control: RX/TX
[ 8.222524] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready
标示红色的日志正常吗?意味着什么?
如果需要我再把 dmesg 其它 内容附上。
下面是 kern.log 今天早上的内容:
May 14 09:06:48 filesvr kernel: [ 7.773742] fb0: VESA VGA frame buffer device
May 14 09:06:48 filesvr kernel: [ 7.990149] kjournald starting. Commit interval 5 seconds
May 14 09:06:48 filesvr kernel: [ 7.990575] EXT3-fs (dm-3): using internal journal
May 14 09:06:48 filesvr kernel: [ 7.990580] EXT3-fs (dm-3): mounted filesystem with ordered data mode
May 14 09:06:48 filesvr kernel: [ 8.183566] type=1400 audit(1368493608.699:11): apparmor="STATUS" operation="profile_load" name="/usr/sbin/named" pid=1052 comm="apparmor_parser"
May 14 09:06:48 filesvr kernel: [ 8.221696] igb: eth0 NIC Link is Up 100 Mbps Full Duplex, Flow Control: RX/TX
May 14 09:06:48 filesvr kernel: [ 8.222524] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready
May 14 09:06:48 filesvr kernel: [ 8.450165] NET: Registered protocol family 15
May 14 09:06:49 filesvr kernel: [ 8.490823] Initializing XFRM netlink socket
May 14 09:06:49 filesvr kernel: [ 9.060427] igb: eth1 NIC Link is Up 1000 Mbps Full Duplex, Flow Control: RX
May 14 09:06:49 filesvr kernel: [ 9.061365] IPv6: ADDRCONF(NETDEV_CHANGE): eth1: link becomes ready
May 14 09:22:37 filesvr kernel: [ 955.578946] IPv6: ADDRCONF(NETDEV_UP): eth0: link is not ready
May 14 09:22:39 filesvr kernel: [ 957.002321] igb: eth0 NIC Link is Up 100 Mbps Full Duplex, Flow Control: RX/TX
May 14 09:22:39 filesvr kernel: [ 957.003458] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready
May 14 09:32:28 filesvr kernel: [ 1545.712290] igb: eth0 NIC Link is Down
May 14 09:32:30 filesvr kernel: [ 1547.342094] igb: eth0 NIC Link is Up 100 Mbps Full Duplex, Flow Control: RX/TX
May 14 11:37:42 filesvr kernel: [ 9047.301720] IPv6: ADDRCONF(NETDEV_UP): eth0: link is not ready
May 14 11:37:44 filesvr kernel: [ 9048.701819] igb: eth0 NIC Link is Up 100 Mbps Full Duplex, Flow Control: RX/TX
May 14 11:37:44 filesvr kernel: [ 9048.702956] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready
May 14 13:09:17 filesvr kernel: [14532.466280] Netfilter messages via NETLINK v0.30.
May 14 13:09:17 filesvr kernel: [14532.476991] ctnetlink v0.93: registering with nfnetlink.
May 14 13:15:57 filesvr kernel: [14932.597650] IPv6: ADDRCONF(NETDEV_UP): eth0: link is not ready
May 14 13:15:59 filesvr kernel: [14933.997054] igb: eth0 NIC Link is Up 100 Mbps Full Duplex, Flow Control: RX/TX
May 14 13:15:59 filesvr kernel: [14933.998197] IPv6: ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready
May 14 13:17:41 filesvr kernel: [15035.784712] device eth0 entered promiscuous mode
May 14 13:26:38 filesvr kernel: [15571.844158] device eth0 left promiscuous mode
May 14 13:26:50 filesvr kernel: [15584.335251] device eth0 entered promiscuous mode
多谢赐教。
|
|