Hello Group,
Equipment: WAG54GX2 SRX200 - Latest Firmware (V1.00.09)
Wifi: Enabled, SSID Hidden, Mac Address Filtering Active, WPA
Encryption
The problem:
Accessed the router through command line (telnet) as usual to check
various stats.
Noticed that load average as follows:
-------Extract of Sysinfo--------
# sysinfo
Number of processes: 35
6:12pm up 1 day, 8:51,
load average: 1 min:1.44, 5 min:1.33, 15 min:1.27
total used free shared
buffers
Mem: 29600 17088 12512 0
2700
Swap: 0 0 0
Total: 29600 17088 12512
-------Extract of Sysinfo--------
Issued ps-aux and not abnormal process was noticed but the load
average appear to be constant at above values over 1, 5 and 15 minutes
which indicate an overload on router.
Checked the 2 wireless connected computers and nothing appears
abnormal.
On one of the wireless computer, I am performing a large file download
consuming full bandwidth of the connection but that should not trigger
the router load to this level.
Finally checked the /var/log/messages and there appear to be some in
some order garbage that is not meaning anything or indicating an
attack as below extract shows:
---/var/log/messagess---
Fri, 2007-08-03 21:18:12 - 0x81542140: B7 B3 2A 1B 8C FD 0D 88 E8 8F
B1 01 51 7E E1 98
Fri, 2007-08-03 21:18:12 - F 10 D7 60
Fri, 2007-08-03 21:18:12 - 0x81331590: A3 67 2E DA 9E 8D 75 84 AE A4
21 A5 8A 54 FC 28
Fri, 2007-08-03 21:18:12 - 0x813315A0: C6 87 34 60 F0 9B CF AE 20 FA
53 94 3C 91 8E EA
Fri, 2007-08-03 21:18:12 - 0x813315B0: A9 80 FB A7 BE 42 54 94 E3 CA
CF 21 94 73 4F 99
Fri, 2007-08-03 21:18:12 - 0x813315C0: 81 5F D3 6F 39 0A 63 5E 85 39
22 D5 32 28 27 AF
Fri, 2007-08-03 21:18:12 - 0x813315D0: 09 C0 83 BA DB A8 F4 12 48 2C
C6 51 86 4F 7D CB
Fri, 2007-08-03 21:18:12 - 0x813315E0: BE 61 CC 11 95 2A EA 4E 1D 21
AA 12 2C 6D 0E 8B
Fri, 2007-08-03 21:18:12 - 0x813315F0: D7 B0 D4 AD 9E 7C DE 77 47 B0
6D 05 DD 38 94 76
Fri, 2007-08-03 21:18:12 -
Fri, 2007-08-03 21:18:12 -
Fri, 2007-08-03 21:18:12 - 0x81650180: 00 00 00 00 60 00 00 00 00 00
00 00 09 2A 5F 00
Fri, 2007-08-03 21:18:12 - 0x81650190: 00 00 00 50 00 00 00 07 00 00
00 00 00 00 00 00
Fri, 2007-08-03 21:18:12 - 0x816501A0: 00 00 00 00 00 00 00 00 08 42
00 00 00 13 CE CB
---/var/log/messagess---
Questions:
1. What is causing the increase of the load, is it the download of a
large file?
2. What can be interrupted from above messages.
Thanks in advance.
-aljuhani
|