Server blocks all connection at midnight
Posted: 26 Feb 2013, 23:03
Hello All,
We have a server that blocks all connection at midnight everyday. We have the same configuration on about 50 severs without any issue. I tried to reinstall CSF, update kernel, iptables -F, etc. I did not find the answer.
Here the logs :
====================================================
Feb 27 00:00:02 lfd[71778]: TERM
Feb 27 00:00:02 lfd[71778]: daemon stopped
Feb 27 00:00:02 lfd[77894]: daemon started on XXXXXX - csf v6.00 (cPanel)
Feb 27 00:00:02 lfd[77894]: CSF Tracking...
Feb 27 00:00:02 lfd[77894]: IPv6 Enabled...
Feb 27 00:00:02 lfd[77894]: LOAD Tracking...
Feb 27 00:00:02 lfd[77894]: DSHIELD Tracking...
Feb 27 00:00:02 lfd[77894]: SPAMHAUS Tracking...
Feb 27 00:00:02 lfd[77894]: TOR Tracking...
Feb 27 00:00:02 lfd[77894]: BOGON Tracking...
Feb 27 00:00:02 lfd[77894]: Country Code Filters...
Feb 27 00:00:02 lfd[77894]: Country Code Lookups...
Feb 27 00:00:02 lfd[77894]: System Integrity Tracking...
Feb 27 00:00:02 lfd[77894]: Exploit Tracking...
Feb 27 00:00:02 lfd[77894]: Email Queue Tracking...
Feb 27 00:00:02 lfd[77894]: Email Relay Tracking...
Feb 27 00:00:02 lfd[77894]: Temp to Perm Block Tracking...
Feb 27 00:00:02 lfd[77894]: System Statistics...
Feb 27 00:00:02 lfd[77894]: Port Scan Tracking...
Feb 27 00:00:02 lfd[77894]: Connection Tracking...
Feb 27 00:00:03 lfd[77894]: Account Tracking...
Feb 27 00:00:03 lfd[77894]: SSH Tracking...
Feb 27 00:00:03 lfd[77894]: SU Tracking...
Feb 27 00:00:03 lfd[77894]: Console Tracking...
Feb 27 00:00:03 lfd[77894]: WHM Tracking...
Feb 27 00:00:03 lfd[77894]: Watching /var/log/maillog...
Feb 27 00:00:03 lfd[77894]: Watching /var/log/exim_mainlog...
Feb 27 00:00:03 lfd[77894]: Watching /var/log/messages...
Feb 27 00:00:03 lfd[77894]: Watching /var/log/secure...
Feb 27 00:00:03 lfd[77894]: Watching /usr/local/cpanel/logs/login_log...
Feb 27 00:00:03 lfd[77894]: Watching /usr/local/apache/logs/error_log...
Feb 27 00:00:03 lfd[77894]: Watching /usr/local/cpanel/logs/access_log...
====================================================
====================================================
root@[~]# uname -a
Linux 2.6.18-408.8.2.el5.lve0.8.61.3 #1 SMP Wed Jul 11 06:49:35 EDT 2012 x86_64 x86_64 x86_64 GNU/Linux
====================================================
Thanks in advance,
We have a server that blocks all connection at midnight everyday. We have the same configuration on about 50 severs without any issue. I tried to reinstall CSF, update kernel, iptables -F, etc. I did not find the answer.
Here the logs :
====================================================
Feb 27 00:00:02 lfd[71778]: TERM
Feb 27 00:00:02 lfd[71778]: daemon stopped
Feb 27 00:00:02 lfd[77894]: daemon started on XXXXXX - csf v6.00 (cPanel)
Feb 27 00:00:02 lfd[77894]: CSF Tracking...
Feb 27 00:00:02 lfd[77894]: IPv6 Enabled...
Feb 27 00:00:02 lfd[77894]: LOAD Tracking...
Feb 27 00:00:02 lfd[77894]: DSHIELD Tracking...
Feb 27 00:00:02 lfd[77894]: SPAMHAUS Tracking...
Feb 27 00:00:02 lfd[77894]: TOR Tracking...
Feb 27 00:00:02 lfd[77894]: BOGON Tracking...
Feb 27 00:00:02 lfd[77894]: Country Code Filters...
Feb 27 00:00:02 lfd[77894]: Country Code Lookups...
Feb 27 00:00:02 lfd[77894]: System Integrity Tracking...
Feb 27 00:00:02 lfd[77894]: Exploit Tracking...
Feb 27 00:00:02 lfd[77894]: Email Queue Tracking...
Feb 27 00:00:02 lfd[77894]: Email Relay Tracking...
Feb 27 00:00:02 lfd[77894]: Temp to Perm Block Tracking...
Feb 27 00:00:02 lfd[77894]: System Statistics...
Feb 27 00:00:02 lfd[77894]: Port Scan Tracking...
Feb 27 00:00:02 lfd[77894]: Connection Tracking...
Feb 27 00:00:03 lfd[77894]: Account Tracking...
Feb 27 00:00:03 lfd[77894]: SSH Tracking...
Feb 27 00:00:03 lfd[77894]: SU Tracking...
Feb 27 00:00:03 lfd[77894]: Console Tracking...
Feb 27 00:00:03 lfd[77894]: WHM Tracking...
Feb 27 00:00:03 lfd[77894]: Watching /var/log/maillog...
Feb 27 00:00:03 lfd[77894]: Watching /var/log/exim_mainlog...
Feb 27 00:00:03 lfd[77894]: Watching /var/log/messages...
Feb 27 00:00:03 lfd[77894]: Watching /var/log/secure...
Feb 27 00:00:03 lfd[77894]: Watching /usr/local/cpanel/logs/login_log...
Feb 27 00:00:03 lfd[77894]: Watching /usr/local/apache/logs/error_log...
Feb 27 00:00:03 lfd[77894]: Watching /usr/local/cpanel/logs/access_log...
====================================================
====================================================
root@[~]# uname -a
Linux 2.6.18-408.8.2.el5.lve0.8.61.3 #1 SMP Wed Jul 11 06:49:35 EDT 2012 x86_64 x86_64 x86_64 GNU/Linux
====================================================
Thanks in advance,