<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<title type="html"><![CDATA[iRedMail — Large I/O on server (DDoS or whatever...)]]></title>
	<link rel="self" href="http://www.iredmail.org/forum/feed-atom-topic4428.xml" />
	<updated>2013-02-06T14:35:38Z</updated>
	<generator>PunBB</generator>
	<id>http://www.iredmail.org/forum/topic4428-large-io-on-server-ddos-or-whatever.html</id>
		<entry>
			<title type="html"><![CDATA[Re: Large I/O on server (DDoS or whatever...)]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post20217.html#p20217" />
			<content type="html"><![CDATA[<p>I wanted to know if someone experienced the same problem. iRedMail is uninstalled from the server now and I will install it again on another one these days. Also I hope that I will make it run in full capability this time.</p><p>Thank you for assistance anyway.</p>]]></content>
			<author>
				<name><![CDATA[grouchy]]></name>
				<uri>http://www.iredmail.org/forum/user32553.html</uri>
			</author>
			<updated>2013-02-06T14:35:38Z</updated>
			<id>http://www.iredmail.org/forum/post20217.html#p20217</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Re: Large I/O on server (DDoS or whatever...)]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post20182.html#p20182" />
			<content type="html"><![CDATA[<p>No idea why it happened on your server since there&#039;s no many info in your description. Here are my questions:</p><p>- Was it caused by email deliveries on local server?<br />- Do you have Fail2ban installed? Any info in its log file?</p>]]></content>
			<author>
				<name><![CDATA[ZhangHuangbin]]></name>
				<uri>http://www.iredmail.org/forum/user2.html</uri>
			</author>
			<updated>2013-02-04T16:05:59Z</updated>
			<id>http://www.iredmail.org/forum/post20182.html#p20182</id>
		</entry>
		<entry>
			<title type="html"><![CDATA[Large I/O on server (DDoS or whatever...)]]></title>
			<link rel="alternate" href="http://www.iredmail.org/forum/post20147.html#p20147" />
			<content type="html"><![CDATA[<p>- iRedMail version: from 0.7.0 updated to 0.8.3<br />- Store mail accounts in which backend (MySQL): <br />- Linux/BSD distribution name and version: Debian Squeeze<br />====</p><p>Today I was faced with strange problem. Catastrophic response from my server.</p><p>iostat showed me a large I/O. <strong>Tps</strong> on disk (600-800) and <strong>avg-cpu %idle</strong> parameter high CPU usage (0.03). That situation was constantly for hours.<br /></p><div class="quotebox"><blockquote><p>$ iostat<br />avg-cpu:&nbsp; %user&nbsp; &nbsp; &nbsp; %nice&nbsp; &nbsp; %system&nbsp; &nbsp; %iowait&nbsp; &nbsp; &nbsp;%steal&nbsp; &nbsp; &nbsp; %idle<br />&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;42.93&nbsp; &nbsp; &nbsp; &nbsp;0.00&nbsp; &nbsp; &nbsp; &nbsp;42.35&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 14.69&nbsp; &nbsp; &nbsp; &nbsp;0.00&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 0.03</p><p>Device:&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; tps&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Blk_read/s&nbsp; &nbsp; &nbsp;Blk_wrtn/s&nbsp; &nbsp; &nbsp; &nbsp; Blk_read&nbsp; &nbsp; &nbsp; &nbsp; Blk_wrtn<br />sda&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 727.68&nbsp; &nbsp; &nbsp; &nbsp; 3763.78&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;8132.43&nbsp; &nbsp; &nbsp; &nbsp; &nbsp;17387617&nbsp; &nbsp; &nbsp;37569536</p></blockquote></div><p>I checked incoming sources to my server and was terrified. 50+ IPs from around the world sending requests. (it is impossible to be a visitors, because the web presentation is from small country with local domain and have 5-15 visits per day)</p><div class="quotebox"><blockquote><p>$ netstat -ntu | awk &#039;{print $5}&#039; | cut -d: -f1 | sort | uniq -c | sort -n</p><p>&nbsp; &nbsp; &nbsp; 1 108.23.241.78<br />&nbsp; &nbsp; &nbsp; 1 113.208.32.112<br />&nbsp; &nbsp; &nbsp; 1 115.114.58.8<br />&nbsp; &nbsp; &nbsp; 1 12.154.55.40<br />&nbsp; &nbsp; &nbsp; 1 12.34.246.167<br />&nbsp; &nbsp; &nbsp; 1 130.206.18.132<br />&nbsp; &nbsp; &nbsp; 1 138.141.100.73<br />&nbsp; &nbsp; &nbsp; 1 158.109.36.179<br />&nbsp; &nbsp; &nbsp; 1 174.132.149.218<br />&nbsp; &nbsp; &nbsp; 1 193.222.78.6<br />&nbsp; &nbsp; &nbsp; 1 193.222.84.70<br />&nbsp; &nbsp; &nbsp; 1 193.38.113.62<br />&nbsp; &nbsp; &nbsp; 1 195.186.227.50<br />&nbsp; &nbsp; &nbsp; 1 195.186.99.50<br />&nbsp; &nbsp; &nbsp; 1 199.250.129.2<br />&nbsp; &nbsp; &nbsp; 1 200.230.71.10<br />&nbsp; &nbsp; &nbsp; 1 200.230.71.55<br />&nbsp; &nbsp; &nbsp; 1 205.166.218.186<br />&nbsp; &nbsp; &nbsp; 1 205.178.149.7<br />&nbsp; &nbsp; &nbsp; 1 205.188.100.58<br />&nbsp; &nbsp; &nbsp; 1 205.188.159.42<br />&nbsp; &nbsp; &nbsp; 1 205.188.190.2<br />&nbsp; &nbsp; &nbsp; 1 205.188.59.193<br />&nbsp; &nbsp; &nbsp; 1 207.115.17.26<br />&nbsp; &nbsp; &nbsp; 1 207.172.157.20<br />&nbsp; &nbsp; &nbsp; 1 207.46.163.30<br />&nbsp; &nbsp; &nbsp; 1 208.36.123.165<br />&nbsp; &nbsp; &nbsp; 1 208.70.88.10<br />&nbsp; &nbsp; &nbsp; 1 208.91.197.128<br />&nbsp; &nbsp; &nbsp; 1 209.145.111.61<br />&nbsp; &nbsp; &nbsp; 1 209.33.205.5<br />&nbsp; &nbsp; &nbsp; 1 212.166.70.250<br />&nbsp; &nbsp; &nbsp; 1 212.170.233.86<br />&nbsp; &nbsp; &nbsp; 1 212.59.199.125<br />&nbsp; &nbsp; &nbsp; 1 213.221.143.235<br />&nbsp; &nbsp; &nbsp; 1 213.46.255.200<br />&nbsp; &nbsp; &nbsp; 1 213.55.128.8<br />&nbsp; &nbsp; &nbsp; 1 213.55.128.9<br />&nbsp; &nbsp; &nbsp; 1 216.99.131.15<br />&nbsp; &nbsp; &nbsp; 1 216.99.131.16<br />&nbsp; &nbsp; &nbsp; 1 217.114.0.53<br />&nbsp; &nbsp; &nbsp; 1 217.76.128.34<br />&nbsp; &nbsp; &nbsp; 1 220.181.15.194<br />&nbsp; &nbsp; &nbsp; 1 50.19.104.123<br />&nbsp; &nbsp; &nbsp; 1 62.14.4.83<br />&nbsp; &nbsp; &nbsp; 1 62.201.1.2<br />&nbsp; &nbsp; &nbsp; 1 64.12.90.34<br />&nbsp; &nbsp; &nbsp; 1 64.12.90.65<br />&nbsp; &nbsp; &nbsp; 1 64.12.90.97<br />&nbsp; &nbsp; &nbsp; 1 64.12.90.98<br />&nbsp; &nbsp; &nbsp; 1 65.205.78.58<br />&nbsp; &nbsp; &nbsp; 1 65.55.39.12<br />&nbsp; &nbsp; &nbsp; 1 65.55.92.136<br />&nbsp; &nbsp; &nbsp; 1 66.232.205.163<br />&nbsp; &nbsp; &nbsp; 1 66.246.235.44<br />&nbsp; &nbsp; &nbsp; 1 66.40.20.29<br />&nbsp; &nbsp; &nbsp; 1 67.220.48.93<br />&nbsp; &nbsp; &nbsp; 1 68.232.135.213<br />&nbsp; &nbsp; &nbsp; 1 69.64.147.249<br />&nbsp; &nbsp; &nbsp; 1 72.167.238.201<br />&nbsp; &nbsp; &nbsp; 1 72.9.240.201<br />&nbsp; &nbsp; &nbsp; 1 74.54.41.162<br />&nbsp; &nbsp; &nbsp; 1 80.64.32.18<br />&nbsp; &nbsp; &nbsp; 1 80.67.172.24<br />&nbsp; &nbsp; &nbsp; 1 82.98.86.161<br />&nbsp; &nbsp; &nbsp; 1 82.98.86.167<br />&nbsp; &nbsp; &nbsp; 1 89.108.104.4<br />&nbsp; &nbsp; &nbsp; 1 94.189.240.125<br />&nbsp; &nbsp; &nbsp; 1 98.139.214.154<br />&nbsp; &nbsp; &nbsp; 1 Address<br />&nbsp; &nbsp; &nbsp; 1 servers)<br />&nbsp; &nbsp; &nbsp; 2 <br />&nbsp; &nbsp; &nbsp; 2 12.102.252.75<br />&nbsp; &nbsp; &nbsp; 2 205.188.103.1<br />&nbsp; &nbsp; &nbsp; 2 205.188.103.2<br />&nbsp; &nbsp; &nbsp; 2 205.188.146.193<br />&nbsp; &nbsp; &nbsp; 2 205.188.156.193<br />&nbsp; &nbsp; &nbsp; 2 209.202.254.14<br />&nbsp; &nbsp; &nbsp; 2 212.40.2.32<br />&nbsp; &nbsp; &nbsp; 2 212.82.111.207<br />&nbsp; &nbsp; &nbsp; 2 213.133.98.98<br />&nbsp; &nbsp; &nbsp; 2 64.12.137.162<br />&nbsp; &nbsp; &nbsp; 2 64.12.90.33<br />&nbsp; &nbsp; &nbsp; 2 64.38.116.12<br />&nbsp; &nbsp; &nbsp; 2 71.74.56.244<br />&nbsp; &nbsp; &nbsp; 2 77.238.177.9<br />&nbsp; &nbsp; &nbsp; 3 205.188.155.110<br />&nbsp; &nbsp; &nbsp; 3 213.133.100.100<br />&nbsp; &nbsp; &nbsp; 3 64.12.137.161<br />&nbsp; &nbsp; &nbsp; 3 65.54.188.110<br />&nbsp; &nbsp; &nbsp; 3 65.55.37.104<br />&nbsp; &nbsp; &nbsp; 3 65.55.37.120<br />&nbsp; &nbsp; &nbsp; 3 65.55.37.88<br />&nbsp; &nbsp; &nbsp; 3 65.55.92.152<br />&nbsp; &nbsp; &nbsp; 3 65.55.92.184<br />&nbsp; &nbsp; &nbsp; 3 71.74.56.243<br />&nbsp; &nbsp; &nbsp; 3 77.238.184.241<br />&nbsp; &nbsp; &nbsp; 3 80.57.35.169<br />&nbsp; &nbsp; &nbsp; 4 204.127.208.75<br />&nbsp; &nbsp; &nbsp; 4 205.188.146.194<br />&nbsp; &nbsp; &nbsp; 4 64.12.139.193<br />&nbsp; &nbsp; &nbsp; 4 65.54.188.126<br />&nbsp; &nbsp; &nbsp; 4 65.55.37.72<br />&nbsp; &nbsp; &nbsp; 5 65.54.188.72<br />&nbsp; &nbsp; &nbsp; 5 65.54.188.94<br />&nbsp; &nbsp; &nbsp; 6 65.55.92.168<br />&nbsp; &nbsp; &nbsp; 8 68.1.17.3<br />&nbsp; &nbsp; &nbsp;11 61.19.251.167<br />&nbsp; &nbsp; &nbsp;13 115.78.225.198<br />&nbsp; &nbsp; &nbsp;13 68.6.19.3<br />&nbsp; &nbsp; &nbsp;13 98.138.206.39<br />&nbsp; &nbsp; &nbsp;14 173.194.70.27<br />&nbsp; &nbsp; &nbsp;14 66.216.129.171<br />&nbsp; &nbsp; &nbsp;16 115.115.125.50<br />&nbsp; &nbsp; &nbsp;18 98.136.217.192<br />&nbsp; &nbsp; &nbsp;23 190.69.78.140<br />&nbsp; &nbsp; &nbsp;57 91.119.178.10</p></blockquote></div><p>So after I tried to stop apache, turn off server for a while, drop packets from couple IPs:</p><div class="quotebox"><blockquote><p>$ /sbin/iptables -I INPUT -s x.x.x.x -p tcp -j DROP<br />$ /sbin/iptables -I INPUT -s x.x.x.x -p udp -j DROP</p></blockquote></div><p>result was the same. </p><p>I installed iRedMail 15 days ago, so I decided to try uninstall and to my surprise that solved a problem tps on disk (2.07) and avg-cpu %idle parameter high CPU usage (97.81).</p><p><strong>Really liked iRedMail solution so I would like to consult with someone on this forum about which configuration of iRedMail could cause this situation at all.</strong></p>]]></content>
			<author>
				<name><![CDATA[grouchy]]></name>
				<uri>http://www.iredmail.org/forum/user32553.html</uri>
			</author>
			<updated>2013-01-31T20:41:38Z</updated>
			<id>http://www.iredmail.org/forum/post20147.html#p20147</id>
		</entry>
</feed>
