<table cellspacing="0" cellpadding="0" border="0" ><tr><td valign="top" style="font: inherit;">Dear Robert<br><br>Are you at live IP ???<br><br>--- On <b>Sun, 7/31/11, Robert-iPhone <i><rhuddleston@gmail.com></i></b> wrote:<br><blockquote style="border-left: 2px solid rgb(16, 16, 255); margin-left: 5px; padding-left: 5px;"><br>From: Robert-iPhone <rhuddleston@gmail.com><br>Subject: Re: [asterisk-users] sip attacks<br>To: "Asterisk Users Mailing List - Non-Commercial Discussion" <asterisk-users@lists.digium.com><br>Cc: "Asterisk Users Mailing List - Non-Commercial Discussion" <asterisk-users@lists.digium.com><br>Date: Sunday, July 31, 2011, 4:26 PM<br><br><div class="plainMail">hard to equate sip attack to ping performance.. Run mtr for a bit.<br>Also try tcpdump or wireshark or tethereal.<br>If you are really paranoid recycle all your passwords<br><br>Sent from my iPhone<br><br>On Jul 31, 2011, at 7:04 PM, "Dave George" <<a
ymailto="mailto:dgeorge@teletoneinc.com" href="/mc/compose?to=dgeorge@teletoneinc.com">dgeorge@teletoneinc.com</a>> wrote:<br><br>> My asterisk server is getting bogged down every 5 minutes. My ping time is<br>> going from 60ms to 800 ms and the call quality is bad.<br>> <br>> I have fail2ban running and I am using iptables. I have two ip connections<br>> to the box.<br>> <br>> How can I tell if the poor performance is due to sip attacks? I don't see<br>> any reg attempts in my asterisk cli. I use to get frequent attacks but<br>> fail2ban seems to be taking care of that.<br>> <br>> See how ping time gets worst in a short space of time and server performance<br>> at the time:<br>> <br>> <br>> 64 bytes from 4.2.2.1: icmp_seq=6 ttl=55 time=87.8 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=7 ttl=55 time=99.8 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=8 ttl=55 time=107
ms<br>> 64 bytes from 4.2.2.1: icmp_seq=9 ttl=55 time=115 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=10 ttl=55 time=120 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=11 ttl=55 time=122 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=12 ttl=55 time=123 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=13 ttl=55 time=126 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=14 ttl=55 time=122 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=15 ttl=55 time=142 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=16 ttl=55 time=142 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=17 ttl=55 time=137 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=18 ttl=55 time=186 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=19 ttl=55 time=255 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=20 ttl=55 time=310 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=21 ttl=55 time=387 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=22 ttl=55 time=445 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=23 ttl=55 time=514 ms<br>> 64 bytes from 4.2.2.1:
icmp_seq=24 ttl=55 time=583 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=25 ttl=55 time=650 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=26 ttl=55 time=715 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=27 ttl=55 time=783 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=28 ttl=55 time=821 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=29 ttl=55 time=810 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=30 ttl=55 time=832 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=31 ttl=55 time=812 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=32 ttl=55 time=821 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=33 ttl=55 time=826 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=34 ttl=55 time=815 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=35 ttl=55 time=821 ms<br>> 64 bytes from 4.2.2.1: icmp_seq=36 ttl=55 time=824 ms<br>> <br>> top - 19:02:38 up 4 days, 11:26, 4 users, load average: 0.36, 0.75, 0.82<br>> Mem: 4051312k total, 1062964k used, 2988348k
free, 167004k buffers<br>> Swap: 6094840k total, 0k used, 6094840k free, 680144k cached<br>> <br>> PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND<br>> 4245 root 15 0 791m 86m 10m S 39.6 2.2 1192:32 asterisk<br>> 18280 root 15 0 3812 600 516 S 2.0 0.0 0:59.00 pppoe<br>> 2582 root 15 0 5912 628 504 S 0.3 0.0 2:02.19 syslogd<br>> 18978 root 15 0 12744 1096 812 R 0.3 0.0 0:00.02 top<br>> 1 root 15 0 10352 700 588
S 0.0 0.0 0:01.14 init<br>> 2 root RT -5 0 0 0 S 0.0 0.0 0:00.01 migration/0<br>> 3 root 34 19 0 0 0 S 0.0 0.0 0:31.90 ksoftirqd/0<br>> 4 root RT -5 0 0 0 S 0.0 0.0 0:00.00 watchdog/0<br>> 5 root RT -5 0 0 0 S 0.0 0.0 0:00.01 migration/1<br>> 6 root 34 19 0 0 0 S 0.0 0.0 0:08.43 ksoftirqd/1<br>> 7 root
RT -5 0 0 0 S 0.0 0.0 0:00.00 watchdog/1<br>> 8 root RT -5 0 0 0 S 0.0 0.0 0:00.13 migration/2<br>> 9 root 34 19 0 0 0 S 0.0 0.0 2:40.56 ksoftirqd/2<br>> 10 root RT -5 0 0 0 S 0.0 0.0 0:00.00 watchdog/2<br>> 11 root RT -5 0 0 0 S 0.0 0.0 0:00.05 migration/3<br>> 12 root 34 19 0 0 0
S 0.0 0.0 0:44.56 ksoftirqd/3<br>> 13 root RT -5 0 0 0 S 0.0 0.0 0:00.00 watchdog/3<br>> 14 root 10 -5 0 0 0 S 0.0 0.0 0:00.02 events/0<br>> 15 root 10 -5 0 0 0 S 0.0 0.0 0:00.00 events/1<br>> 16 root 10 -5 0 0 0 S 0.0 0.0 0:00.00 events/2<br>> 17 root 10 -5 0 0 0 S 0.0 0.0 0:00.00
events/3<br>> 18 root 10 -5 0 0 0 S 0.0 0.0 0:00.00 khelper<br>> 55 root 10 -5 0 0 0 S 0.0 0.0 0:00.00 kthread<br>> 62 root 10 -5 0 0 0 S 0.0 0.0 0:00.07 kblockd/0<br>> 63 root 10 -5 0 0 0 S 0.0 0.0 0:00.01 kblockd/1<br>> 64 root 10 -5 0 0 0 S 0.0 0.0 0:00.00 kblockd/2<br>> 65 root 10 -5
0 0 0 S 0.0 0.0 0:00.00 kblockd/3<br>> 66 root 17 -5 0 0 0 S 0.0 0.0 0:00.00 kacpid<br>> 166 root 17 -5 0 0 0 S 0.0 0.0 0:00.00 cqueue/0<br>> 167 root 18 -5 0 0 0 S 0.0 0.0 0:00.00 cqueue/1<br>> <br>> <br>> <br>> Dave<br>> <br>> <br>> <br>> --<br>> _____________________________________________________________________<br>> -- Bandwidth and Colocation Provided by <a href="http://www.api-digital.com" target="_blank">http://www.api-digital.com</a> --<br>> New to Asterisk? Join us for a live introductory
webinar every Thurs:<br>> <a href="http://www.asterisk.org/hello" target="_blank">http://www.asterisk.org/hello</a><br>> <br>> asterisk-users mailing list<br>> To UNSUBSCRIBE or update options visit:<br>> <a href="http://lists.digium.com/mailman/listinfo/asterisk-users" target="_blank">http://lists.digium.com/mailman/listinfo/asterisk-users</a><br><br>--<br>_____________________________________________________________________<br>-- Bandwidth and Colocation Provided by <a href="http://www.api-digital.com" target="_blank">http://www.api-digital.com</a> --<br>New to Asterisk? Join us for a live introductory webinar every Thurs:<br> <a href="http://www.asterisk.org/hello" target="_blank">http://www.asterisk.org/hello</a><br><br>asterisk-users mailing list<br>To UNSUBSCRIBE or update options
visit:<br> <a href="http://lists.digium.com/mailman/listinfo/asterisk-users" target="_blank">http://lists.digium.com/mailman/listinfo/asterisk-users</a><br></div></blockquote></td></tr></table>