This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Webadmin-User or Password invalid -- > Heavy usage

This morning, i tried to start login webadmin, but could not. Invalid Username or Passwort. So, I tried with the admin account, the same happened (Rest on the FW was working). On the console I could login with loginuser without problem. About 20 minutes later, the login worked again. I could see, that I had a heavy CPU usage (>90%) and I think that was the problem. 
I checked the content filter log and I could see that one workstation tried to access to : 

2008:01:23-09:10:03 (none) httpproxy[5252]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="block" method="GET" srcip="184.2.1.207" user="U284230" statuscode="407" cached="0" profile="profile_1" filteraction="" size="2242" time="14 ms" request="0xad0233b0" url="google.de/favicon.ico" error=""

and

2008:01:23-09:10:03 (none) httpproxy[5252]: id="0001" severity="info" sys="SecureWeb" sub="http" name="http access" action="block" method="GET" srcip="184.2.1.207" user="U284230" statuscode="407" cached="0" profile="profile_1" filteraction="" size="2340" time="102 ms" request="0xad650558" url="download.mozilla.org/

Both pages are blocked for whatever reasons and the workstation tried to access about 10 times per second. Do you have any idea why, or did anyone had a similar problem?


This thread was automatically locked due to age.
Parents
  • Koddi,

    We had a similar problem with a customer today.  The problem survived even a cold reboot.  The solution was to get in with SSH and restart the middleware with:
    \etc\init.d\mdw restart

    We will see if the problem recurs
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Koddi,

    We had a similar problem with a customer today.  The problem survived even a cold reboot.  The solution was to get in with SSH and restart the middleware with:
    \etc\init.d\mdw restart

    We will see if the problem recurs
     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data