Koozali.org: home of the SME Server

/var/log/messages

David L

/var/log/messages
« on: February 18, 2001, 08:41:35 AM »
My recent upgrade to 4.1 has been brought to it's knees by a 300MB /var/log/messages file consisting mostly of Packet log:  denylog DENY eth0 PROTO=17 xxx.xxx.xxx.xxx:137 etc. messages.  It's spending all of it's time on disk access, not serving any web pages.
Did a clean install on a different machine and the same thing was starting to happen.  NTP is disabled.  The only thing the two have in common are realtek ethernet drivers.  Is this what the problem is?

Thanks for the help.

Charlie Brady

Re: /var/log/messages
« Reply #1 on: February 19, 2001, 06:25:39 AM »
David L wrote:

> My recent upgrade to 4.1 has been brought to it's knees by a
> 300MB /var/log/messages file consisting mostly of Packet
> log:  denylog DENY eth0 PROTO=17 xxx.xxx.xxx.xxx:137 etc.
> messages.  It's spending all of it's time on disk access, not
> serving any web pages.
> Did a clean install on a different machine and the same thing
> was starting to happen.  NTP is disabled.  The only thing the
> two have in common are realtek ethernet drivers.  Is this
> what the problem is?

No, the problem is a combination of the new packet filter, and a large number of netbios name requests on your external interface. The external interface is normally connected to the Internet, and there shouldn't be a lot of computers hitting your server with such requests. Perhaps your external interface is instead connected to a network of Windows computers.

Ask again on this forum if you want some pointers on how to block these packets without logging them.

Charlie

David L

Re: /var/log/messages
« Reply #2 on: February 19, 2001, 07:05:09 AM »
Yes I would like these pointers.  My system is on a cablemodem on which you can browse the network neighborhood and see other peoples workgroups and computers which would explain the traffic.

Darrell May

Re: /var/log/messages
« Reply #3 on: February 22, 2001, 10:23:36 AM »
I asked this same question on devinfo and have posted the answer Charlie provided on my web site at:

http://netsourced.com/e-smith/howto-stop-logging.html

Regards,

Darrell

David L

Re: /var/log/messages
« Reply #4 on: February 24, 2001, 08:19:28 AM »
Thanks Darrell.  I appreciate it.