Can't find what you need?


• Ask the Community
• Create a Case
Reset Search
 

 

Article

Switch Reboot and Core Following Repeated Telnet Attempts From Rogue Internet Addresses

« Go Back

Information

 
TitleSwitch Reboot and Core Following Repeated Telnet Attempts From Rogue Internet Addresses
Symptoms
  • Switch rebooted producing two core files following log messages related to telnet error/warnings
CP1 [06/10/19 10:03:38.781:UTC] 0x000305f1 00000000 GlobalRouter SW WARNING Maximum number of login attempts reached for IP X.X.X.X. Lock out for 60 seconds.
CP1 [06/10/19 10:03:39.361:UTC] 0x000e4608 00000000 GlobalRouter SW INFO telnetd: Sorry, Ip locked out.
<NP>000:</NP> 06/10/19 10:03:55.687:UTC] 0The previous message repeated 3 time(s). 
CP1 [06/10/19 10:04:00.693:UTC] 0x000e460b 00000000 GlobalRouter SW WARNING telnetd input: CLI didn't start
IO1 [06/10/19 11:29:48.837:UTC] 0x0027042e 00000000 GlobalRouter SW ERROR Max missed WD feeds for process ssio reached: 0, total missed:3 last timestamp:1987647700026 (000001cec908fc3a)
IO1 [06/10/19 11:29:51.838:UTC] 0x0027042f 00000000 GlobalRouter SW WARNING Aborting process ssio (pid:1778) due to missed watchdog
CP1 [06/10/19 11:29:55.315:UTC] 0x002e8601 00000000 GlobalRouter HCK WARNING Missing heartbeats for process ssio on slot 1
IO1 [06/10/19 11:29:57.092:UTC] 0x0027040c 00000000 GlobalRouter SW INFO Saving flight recorder data
IO1 [06/10/19 11:29:57.521:UTC] 0x0027040d 00000000 GlobalRouter SW INFO Saved flight recorder data in file: /intflash/PMEM/1/pmem.20190610112957.1.tar.gz
IO1 [06/10/19 11:29:57.522:UTC] 0x00270415 00000000 GlobalRouter SW ERROR Crash reporter data: Process Name: ssio, Thread Name: main, Signal: 6, Slot: 1, PID: 1778, LWP: 1778
IO1 [06/10/19 11:29:57.522:UTC] 0x00270415 00000000 GlobalRouter SW ERROR Crash reporter data: [bt] Execution path:
IO1 [06/10/19 11:29:57.522:UTC] 0x00270415 00000000 GlobalRouter SW ERROR Crash reporter data: [bt] /opt/appfs/plat/lib/io/libndlcs.so.1(_Z30nd_lcs_crash_exception_handleriP9siginfo_tPv+0x170)[0
IO1 [06/10/19 11:29:57.522:UTC] 0x00270415 00000000 GlobalRouter SW ERROR Crash reporter data: [bt] 124]
IO1 [06/10/19 11:29:57.522:UTC] 0x00270415 00000000 GlobalRouter SW ERROR Crash reporter data: [bt] linux-vdso32.so.1(__kernel_sigtramp_rt32+0x0)[0x1003d0]
IO1 [06/10/19 11:29:57.522:UTC] 0x00270415 00000000 GlobalRouter SW ERROR Crash reporter data: [bt] ssio(mapCpToCopTable+0x663b)[0x11852273]
IO1 [06/10/19 11:29:57.522:UTC] 0x00270415 00000000 GlobalRouter SW ERROR Crash reporter data: [bt] /opt/appfs/plat/lib/io/libv2l.so.1(v2l_usleep+0x100)[0xfd647c0]
IO1 [06/10/19 11:29:57.522:UTC] 0x00270415 00000000 GlobalRouter SW ERROR Crash reporter data: [bt] /opt/appfs/plat/lib/io/libv2l.so.1(taskDelay+0x130)[0xfd64c7c]
IO1 [06/10/19 11:29:57.522:UTC] 0x00270415 00000000 GlobalRouter SW ERROR Crash reporter data: [bt] ssio(user_syskill+0x34)[0x101ef5ac]
IO1 [06/10/19 11:29:57.522:UTC] 0x00270415 00000000 GlobalRouter SW ERROR Crash reporter data: [bt] ssio(main+0x124)[0x101eeec0]
IO1 [06/10/19 11:29:57.522:UTC] 0x00270415 00000000 GlobalRouter SW ERROR Crash reporter data: [bt] /lib/libc.so.6(+0x23260)[0xeefc260]
CP1 [06/10/19 11:30:11.013:UTC] 0x002e8612 00000000 GlobalRouter HCK INFO Connection closed with handle: 0xb7416508
IO1 [06/10/19 11:30:11.014:UTC] 0x00270407 00000000 GlobalRouter SW ERROR Process ssio (1778) died, exit status: uncaught signal: 6 (core dumped)
  • Backtrace of two cores
Lifecycle Crash Reporter: Process Name: ssio, Thread Name: main, Signal 6, Slot: 1, PID 1778, LWP: 1778
[bt] Execution path:
[bt] /opt/appfs/plat/lib/io/libndlcs.so.1(_Z30nd_lcs_crash_exception_handleriP9siginfo_tPv+0x170)[0xfc57
[bt] 124]
[bt] linux-vdso32.so.1(__kernel_sigtramp_rt32+0x0)[0x1003d0]
[bt] ssio(mapCpToCopTable+0x663b)[0x11852273]
[bt] /opt/appfs/plat/lib/io/libv2l.so.1(v2l_usleep+0x100)[0xfd647c0]
[bt] /opt/appfs/plat/lib/io/libv2l.so.1(taskDelay+0x130)[0xfd64c7c]
[bt] ssio(user_syskill+0x34)[0x101ef5ac]
[bt] ssio(main+0x124)[0x101eeec0]
[bt] /lib/libc.so.6(+0x23260)[0xeefc260]


Lifecycle Crash Reporter: Process Name: cbcp-main.x, Thread Name: main, Signal 6, Slot: 1, PID 1761, LWP: 1761
[bt] Execution path:
[bt] /opt/appfs/lib/cp/libndlcs.so.1(_Z30nd_lcs_crash_exception_handleriP9siginfo_tPv+0x1c8)[0xa46489c]
[bt] linux-vdso32.so.1(__kernel_sigtramp_rt32+0x0)[0x1003d0]
[bt] /opt/appfs/lib/cp/libv2l.so.1(+0x25938)[0xa243938]
[bt] /opt/appfs/lib/cp/libndutl.so.1(nd_utl_nssleep+0x64)[0xfd07f14]
[bt] /opt/appfs/lib/cp/libndutl.so.1(nd_utl_sleep+0x40)[0xfd08014]
[bt] cbcp-main.x(user_syskill+0x20)[0x114bd304]
[bt] cbcp-main.x(main+0x118)[0x1025bba8]
[bt] /lib/libc.so.6(+0x23260)[0x96bb260]
[bt] /lib/libc.so.6(+0x23404)[0x96bb404]
Environment
  • VSP 8400
  • VOSS 7.1.1.0
Cause
Software defect VOSS-14276
Resolution
Upgrade to VOSS 7.1.4 or 8.0.6 release
Additional notes
  • Issue related to attempted logins from rouge addresses on internet where TCP connection is left open while the actual access is not occurring and these TCP connections remain
  • ACL's can be used to mitigate rogue connection attempts when node placed on internet outside of firewall

Feedback

 

Was this article helpful?


   

Feedback

Please tell us how we can make this article more useful.

Characters Remaining: 255