Interconnect interrupts after daily start of Nethserver

NethServer Version: 7.5 1804 Final
Module: Webtop, Rspamd, Dokuwiki, Nextcloud and Mattermost

Hi@all,

I have the following problem:

My Nethserver starts automatically every morning at 07:00. Always shortly after the start the internet connection breaks completely. In the log of the firewall I see the message “Maximum sessions per host (2000) was exceeded ACCESS BLOCK” After a restart of the gateway, the Internet is back, but is interrupted again and again in the course of the day. If the Nethserver is off, the Internet will work without a problem.

What could be the reason for this?

Thanks for your help

Regards

Uwe

Do you have a zyxel firewall?

http://www.zyxelforum.de/usg-110-langsames-internet-t11505.html-view=next

Maybe check the connections on Nethserver with netstat -at to see if there are that much sessions…

You may do a virus scan on your Nethserver with clamav or some AV boot disc/usb.

Servus Markus,

i use a Zyxel UTM Firewall and the mistake in the link is not unknown for me. But this is not my problem.
I’ve set the session limit value to 0 (unlimited). The output of netstat -at shows nothing special

[root@remote ~]# netstat -at
Active Internet connections (servers and established)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 0.0.0.0:smtp 0.0.0.0:* LISTEN
tcp 0 0 localhos:ub-dns-control 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:ldaps 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:sieve 0.0.0.0:* LISTEN
tcp 0 0 localhost:8065 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:imaps 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:pop3s 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:ldap 0.0.0.0:* LISTEN
tcp 0 0 localhost:10053 0.0.0.0:* LISTEN
tcp 0 0 localhost:11334 0.0.0.0:* LISTEN
tcp 0 0 localhost:11335 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:25672 0.0.0.0:* LISTEN
tcp 0 0 localhost:cslistener 0.0.0.0:* LISTEN
tcp 0 0 localhost:55432 0.0.0.0:* LISTEN
tcp 0 0 localhost:etlservicemgr 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:mysql 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:submission 0.0.0.0:* LISTEN
tcp 0 0 localhost:6379 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:pop3 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:imap 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:63503 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:sunrpc 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:sieve-filter 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:urd 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:epmd 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:us-cli 0.0.0.0:* LISTEN
tcp 0 0 0.0.0.0:domain 0.0.0.0:* LISTEN
tcp 0 0 localhost:postgres 0.0.0.0:* LISTEN
tcp 0 0 localhost:52176 localhost:ldap TIME_WAIT
tcp 0 0 localhost:51948 localhost:postgres ESTABLISHED
tcp 0 0 localhost:55432 localhost:49442 ESTABLISHED
tcp 1 0 localhost:55433 localhost:8065 CLOSE_WAIT
tcp 0 0 localhost:39186 localhost:6379 ESTABLISHED
tcp 0 0 localhost:postgres localhost:58014 ESTABLISHED
tcp 0 0 localhost:56354 localhost:8065 ESTABLISHED
tcp 0 0 localhost:postgres localhost:57862 ESTABLISHED
tcp 0 0 localhost:8065 localhost:51726 ESTABLISHED
tcp 0 0 localhost:etlservicemgr localhost:39946 TIME_WAIT
tcp 1 0 localhost:50760 localhost:58080 CLOSE_WAIT
tcp 0 0 localhost:60554 localhost:amqp ESTABLISHED
tcp 0 0 localhost:52610 localhost:postgres ESTABLISHED
tcp 0 0 localhost:postgres localhost:58081 ESTABLISHED
tcp 0 0 localhost:6379 localhost:39186 ESTABLISHED
tcp 0 0 localhost:57936 localhost:imap TIME_WAIT
tcp 0 0 localhost:55432 localhost:49446 ESTABLISHED
tcp 0 0 localhost:55986 localhost:8065 ESTABLISHED
tcp 0 0 localhost:8065 localhost:56114 ESTABLISHED
tcp 0 0 localhost:60562 localhost:amqp ESTABLISHED
tcp 0 0 localhost:55310 localhost:postgres ESTABLISHED
tcp 0 0 localhost:39192 localhost:6379 ESTABLISHED
tcp 0 0 localhost:postgres localhost:58086 ESTABLISHED
tcp 0 0 localhost:ldap localhost:52190 TIME_WAIT
tcp 1 0 localhost:50764 localhost:58080 CLOSE_WAIT
tcp 0 0 localhost:postgres localhost:58082 ESTABLISHED
tcp 0 0 localhost:55230 localhost:58080 TIME_WAIT
tcp 0 0 localhost:postgres localhost:51948 ESTABLISHED
tcp 0 0 localhost:postgres localhost:58084 ESTABLISHED
tcp 0 0 localhost:53824 localhost:postgres ESTABLISHED
tcp 0 0 localhost:51726 localhost:8065 ESTABLISHED
tcp 0 0 localhost:49444 localhost:55432 ESTABLISHED
tcp 0 0 localhost:57862 localhost:postgres ESTABLISHED
tcp 0 0 localhost:postgres localhost:52322 ESTABLISHED
tcp 0 0 localhost:52028 localhost:ldap ESTABLISHED
tcp 0 0 localhost:52172 localhost:ldap TIME_WAIT
tcp 0 0 localhost:60556 localhost:amqp ESTABLISHED
tcp 0 0 localhost:postgres localhost:57022 ESTABLISHED
tcp 0 0 localhost:postgres localhost:56138 ESTABLISHED
tcp 0 0 localhost:52186 localhost:ldap TIME_WAIT
tcp 0 0 remote.xxx-onli:imaps 192.168.154.34:50180 ESTABLISHED
tcp 0 0 localhost:52666 localhost:postgres ESTABLISHED
tcp 0 0 localhost:etlservicemgr localhost:39948 TIME_WAIT
tcp 0 0 localhost:postgres localhost:52976 ESTABLISHED
tcp 0 3312 remote.xxx-onli:63503 192.168.154.34:52668 ESTABLISHED
tcp 0 0 localhost:etlservicemgr localhost:39954 TIME_WAIT
tcp 0 0 localhost:49442 localhost:55432 ESTABLISHED
tcp 1 0 localhost:56174 localhost:8065 CLOSE_WAIT
tcp 0 0 localhost:56114 localhost:8065 ESTABLISHED
tcp 0 0 localhost:6379 localhost:39182 ESTABLISHED
tcp 0 0 localhost:54376 localhost:postgres ESTABLISHED
tcp 0 0 localhost:postgres localhost:57960 ESTABLISHED
tcp 0 0 localhost:55242 localhost:58080 TIME_WAIT
tcp 0 0 localhost:52322 localhost:postgres ESTABLISHED
tcp 0 0 localhost:56138 localhost:postgres ESTABLISHED
tcp 0 0 localhost:55236 localhost:58080 TIME_WAIT
tcp 0 0 localhost:8065 localhost:56354 ESTABLISHED
tcp 0 0 localhost:57946 localhost:imap TIME_WAIT
tcp 0 0 localhost:6379 localhost:39180 ESTABLISHED
tcp 0 0 localhost:imap localhost:57978 TIME_WAIT
tcp 0 0 localhost:52182 localhost:ldap TIME_WAIT
tcp 0 0 localhost:52174 localhost:ldap TIME_WAIT
tcp 0 0 localhost:8065 localhost:55986 ESTABLISHED
tcp 0 0 localhost:epmd localhost:56994 ESTABLISHED
tcp 0 0 localhost:52976 localhost:postgres ESTABLISHED
tcp 0 0 localhost:55432 localhost:49448 ESTABLISHED
tcp 0 0 localhost:postgres localhost:58078 ESTABLISHED
tcp 1 0 localhost:55988 localhost:8065 CLOSE_WAIT
tcp 0 0 localhost:imap localhost:57980 TIME_WAIT
tcp 0 0 localhost:49448 localhost:55432 ESTABLISHED
tcp 0 0 localhost:57022 localhost:postgres ESTABLISHED
tcp 0 0 localhost:56994 localhost:epmd ESTABLISHED
tcp 0 0 localhost:postgres localhost:54376 ESTABLISHED
tcp 0 0 localhost:postgres localhost:55310 ESTABLISHED
tcp 1 0 localhost:55938 localhost:8065 CLOSE_WAIT
tcp 0 0 localhost:49446 localhost:55432 ESTABLISHED
tcp 0 0 localhost:postgres localhost:52666 ESTABLISHED
tcp 0 0 localhost:ldap localhost:52028 ESTABLISHED
tcp 0 0 localhost:56418 localhost:8065 ESTABLISHED
tcp 0 0 localhost:39180 localhost:6379 ESTABLISHED
tcp 0 0 localhost:postgres localhost:53824 ESTABLISHED
tcp 0 0 remote.xxx-onli:imaps 192.168.154.74:59810 ESTABLISHED
tcp 0 0 localhost:55432 localhost:49444 ESTABLISHED
tcp 0 0 localhost:postgres localhost:52610 ESTABLISHED
tcp 0 0 localhost:52184 localhost:ldap TIME_WAIT
tcp 1 0 localhost:55832 localhost:8065 CLOSE_WAIT
tcp 0 0 localhost:6379 localhost:39192 ESTABLISHED
tcp 0 0 localhost:8065 localhost:56418 ESTABLISHED
tcp 1 0 localhost:50762 localhost:58080 CLOSE_WAIT
tcp 0 0 localhost:39182 localhost:6379 ESTABLISHED
tcp 0 0 localhost:postgres localhost:58018 ESTABLISHED
tcp 0 0 localhost:8065 localhost:56174 FIN_WAIT2
tcp 0 0 localhost:postgres localhost:58026 ESTABLISHED
tcp 0 0 localhost:postgres localhost:58016 ESTABLISHED
tcp6 0 0 [::]:58009 [::]:* LISTEN
tcp6 0 0 [::]:smtp [::]:* LISTEN
tcp6 0 0 localhos:ub-dns-control [::]:* LISTEN
tcp6 0 0 [::]:https [::]:* LISTEN
tcp6 0 0 [::]:ldaps [::]:* LISTEN
tcp6 0 0 [::]:sieve [::]:* LISTEN
tcp6 0 0 [::]:8126 [::]:* LISTEN
tcp6 0 0 [::]:58080 [::]:* LISTEN
tcp6 0 0 [::]:irdmi [::]:* LISTEN
tcp6 0 0 [::]:imaps [::]:* LISTEN
tcp6 0 0 [::]:pop3s [::]:* LISTEN
tcp6 0 0 [::]:ldap [::]:* LISTEN
tcp6 0 0 [::]:amqp [::]:* LISTEN
tcp6 0 0 [::]:submission [::]:* LISTEN
tcp6 0 0 [::]:pop3 [::]:* LISTEN
tcp6 0 0 [::]:imap [::]:* LISTEN
tcp6 0 0 [::]:63503 [::]:* LISTEN
tcp6 0 0 [::]:sunrpc [::]:* LISTEN
tcp6 0 0 [::]:webcache [::]:* LISTEN
tcp6 0 0 [::]:http [::]:* LISTEN
tcp6 0 0 [::]:sieve-filter [::]:* LISTEN
tcp6 0 0 [::]:urd [::]:* LISTEN
tcp6 0 0 [::]:epmd [::]:* LISTEN
tcp6 0 0 [::]:us-cli [::]:* LISTEN
tcp6 0 0 [::]:980 [::]:* LISTEN
tcp6 0 0 localhost:58005 [::]:* LISTEN
tcp6 0 0 [::]:domain [::]:* LISTEN
tcp6 0 0 localhost:amqp localhost:60556 ESTABLISHED
tcp6 0 0 localhost:amqp localhost:60554 ESTABLISHED
tcp6 0 0 remote.xxx-onli:https 192.168.154.34:52667 TIME_WAIT
tcp6 0 0 localhost:52202 localhost:ldap TIME_WAIT
tcp6 0 0 remote.xxx-onli:https 192.168.154.74:59815 TIME_WAIT
tcp6 0 0 remote.xxx-onli:https 192.168.154.74:59809 TIME_WAIT
tcp6 0 0 localhost:amqp localhost:60562 ESTABLISHED
tcp6 0 0 remote.xxx-onli:https 192.168.154.74:59816 FIN_WAIT2
tcp6 0 0 remote.xxx-onli:https 192.168.154.74:59817 TIME_WAIT
tcp6 0 0 localhost:58018 localhost:postgres ESTABLISHED
tcp6 0 0 localhost:58086 localhost:postgres ESTABLISHED
tcp6 0 0 remote.xxx-onli:https 192.168.154.74:59818 ESTABLISHED
tcp6 0 0 remote.xxx-onli:https 192.168.154.74:58736 ESTABLISHED
tcp6 0 0 localhost:58016 localhost:postgres ESTABLISHED
tcp6 0 0 localhost:58014 localhost:postgres ESTABLISHED
tcp6 0 0 localhost:52192 localhost:ldap TIME_WAIT
tcp6 0 0 localhost:58078 localhost:postgres ESTABLISHED
tcp6 0 0 localhost:57960 localhost:postgres ESTABLISHED
tcp6 0 0 localhost:58082 localhost:postgres ESTABLISHED
tcp6 0 0 localhost:52204 localhost:ldap TIME_WAIT
tcp6 0 0 localhost:52190 localhost:ldap TIME_WAIT
tcp6 0 0 localhost:57980 localhost:imap TIME_WAIT
tcp6 0 0 remote.xxx-onli:https 192.168.154.34:52666 TIME_WAIT
tcp6 0 0 remote.xxx-onli:https 192.168.154.34:52664 TIME_WAIT
tcp6 0 0 localhost:52196 localhost:ldap TIME_WAIT
tcp6 0 0 localhost:58084 localhost:postgres ESTABLISHED
tcp6 0 0 localhost:58081 localhost:postgres ESTABLISHED
tcp6 0 0 remote.xxx-online:980 192.168.154.74:59813 TIME_WAIT
tcp6 0 0 localhost:58026 localhost:postgres ESTABLISHED
tcp6 0 0 remote.tiedt-online:980 192.168.154.74:59812 TIME_WAIT
tcp6 0 0 localhost:57978 localhost:imap TIME_WAIT
tcp6 0 0 localhost:52198 localhost:ldap TIME_WAIT

Unbenannt
Infected files were not found.

Regards and a nice sunday…

Uwe

1 Like

Could you tell us a bit more about your network setup?
Maybe issue could be nethserver, but also… could be the UTM/Gateway too.

2.000 NAT sessions are enough for home setup, with an internet connection of 10mbits.
Anyway, the “solution” could be reversing issues to NethServer and not to USG.
Do not allow more than 1500 connections par host, this will slow the network operativity for NethServer but will lower the chances to stuck the internet connection.

Otherwise, you can update your gateway with a new device or a “firewall only” Nethserver setup.

1 Like

Hi,

here comes the internet via cable from Unitymedia. Of those I have a FritzBox as a gateway. Behind the gateway comes the Zywall USG Firewall and then a managed Netgear Switch GS 108 T. If the Nethserver is off, there are no problems. But it starts every morning at 07:45 clock and then the problem begins with the interrupted Internet connection. I’ve already reset the USG and reconfigured. The problem remains. Here is a picture from the log of the USG.

The Nethserver tries to connect to the whole world, which is blocked by the USG. Virus scan shows no useful results. The Nethserver works in the DMZ of the USG.

Regards

Uwe

Do you use bind9?

No, i dont use it.

Why nethserver is not kept on?

Nobody has to use the server in the night. And another reason is the high price of electric energy here in Germany.

Hi,

i think i found the mistake. I have completely reinstalled the Nethserver. After installing nethserver-mail2-server the problem starts with the failure of the internet connection. After every start of Nethserver the log of the firewall is full of blocked connection attempts, as you can see in the picture above. What can i do to solve the problem?

Regards

Uwe

Mail2 should download some blacklists, contact different hosts for update (DNS servers, MX Records, SPF, etc etc).

I’m quite… confused…
I installed a 7.3 (still not updated) mailserver into a office with a Zywall 2 Plus firewall as network gateway, Windows as DNS server. Often Zywall2 was “stuck” into too many NAT connections, but was not able to stuck the internet connections of the whole office; this appliance has a 3000 nat session limit and a session limiter par host; it was configured to 2500 hosts. Internet connection was a DSL 14/1mbps

I own an old USG20W (not “VPN” version) appliance, updated to latest firmware published by Zyxel HQ.
The session limiter has a maximum setup of 8192
immagine
with the capability to setup rules for few hosts (for instance 512 as general rule but 2.048 for 4-5 hosts)
immagine

IMHO it’s strange that internet connection stuck like that.
Maybe your ISP use a ratelimiter for your connection? FritzBox do not have ratelimiter for connections, it’s just a matter of memory used by other software functions; 7490 stated “several hundreds” of connections.
https://en.avm.de/service/fritzbox/fritzbox-7490/knowledge-base/publication/show/21_Maximum-number-of-simultaneous-IP-connections/

If mailserver is a public mail server should be 24/7 available. If power consumption is quite too heavy, maybe you can find a bit more power efficient server (old corporate desktops have remarkably efficients PSU with capability of a couple of SATA disks)

1 Like

I have now found that Rspamd is the cause of the disruption of the Internet. When I install only Webtop, everything is fine.

But RSpamD is used in different places… Without causing issues.

While the internet connection is broken, from LAN1 can you access to NethServer into DMZ?

Yes, i have access from LAN1 to the Nethserver in DMZ.
Two days ago, I installed Nethserver as a virtual machine on a Hyper-V 2008 R2. As an application only WebTop and RspamD run on it. The problem remains. Immediately after the installation of RspamD the application telephones with IP addresses all over the world and the internet here is off. This can not be due to theUSG firewall. It’s the same with a Cisco ASA 5505.

Therefore could be an ISP issue…

My provider tells me there are no problems on his side. On 30.09.2018 I reinstalled NS. With all applications as mentioned above but without RspamD. And since then I love my NS again, because he works without problems and without interruption of the Internet connection. I do not necessarily need RspamD because I have the anti-spam application running on the USG. However, RspamD convinced me more.

any news, @transocean?

Yes,

Nethserver works without rspamd. No more interrupt of internet connection.