Project

General

Profile

Actions

Incident #232

closed

node51.p.d4science.research-infrastructures.eu webapp unresponsive. The ajp port is open with connections from China

Added by Andrea Dell'Amico almost 10 years ago. Updated almost 10 years ago.

Status:
Closed
Priority:
Urgent
Category:
System Application
Target version:
Start date:
Jun 06, 2015
Due date:
% Done:

100%

Estimated time:
Infrastructure:
Production

Description

The 8080 (and 8005) tomcat port has been closed since last night.
The actual 'netstat -na' output is:

Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address           Foreign Address         State
tcp        0      0 0.0.0.0:4949            0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:5666            0.0.0.0:*               LISTEN
tcp        0      0 0.0.0.0:8627            0.0.0.0:*               LISTEN
tcp        0      0 146.48.122.127:22       146.48.123.11:54985     ESTABLISHED
tcp6       0      0 :::22                   :::*                    LISTEN
tcp6       0      0 :::45339                :::*                    LISTEN
tcp6       0      0 :::4000                 :::*                    LISTEN
tcp6       0      0 :::4001                 :::*                    LISTEN
tcp6       0      0 146.48.122.127:8009     61.240.144.65:60000     ESTABLISHED
tcp6       0      0 146.48.122.127:8009     61.240.144.67:60000     ESTABLISHED
tcp6       0      0 146.48.122.127:42774    146.48.122.255:6166     ESTABLISHED
udp        0      0 146.48.122.127:55702    239.2.10.67:8627        ESTABLISHED
udp        0      0 146.48.122.127:8627     0.0.0.0:*
udp        0      0 0.0.0.0:8627            0.0.0.0:*
udp6  124860      0 :::4446                 :::*
udp6       0      0 :::4446                 :::*

The two IPs connected to the 8009 (ajp) port are from a chinese network.
The 4446 udp port has been opened by tomcat or one of the running apps, but I don't know the reason.
The load average is costantly around 1.00, while there's no memory pressure.

I completely stopped the tomcat container to get rid of the rogue connections.

Actions

Also available in: Atom PDF

Add picture from clipboard (Maximum size: 8.91 MB)