Alis_Klar Posted October 10, 2007 Posted October 10, 2007 This is a weird one! We have had Censornet 3r1 running for 18 months with no problems. Recently a teacher has been reporting that the internet for the kids (via Censornet) will go down every half hour for 1 minute. This is like clockwork every half hour. MY guess is that some sort of housekeeping script or other process is doing this. As a stab in the dark have done a crontab -l for users admin,root and postgres. Can't su to nobody don't know the password. Any ideas? Also as an aside does anyone know when the new open source (as oposed to paidfor v4) version of censornet is out?
Geoff Posted October 10, 2007 Posted October 10, 2007 Cron logs what it is up to into the syslog. Check in /var/logs/ for a cron logfile or the generic syslog/messages logs.
ChrisH Posted October 10, 2007 Posted October 10, 2007 The most current version is 3.3r6 maybe you should consider upgrading as even r6 is pretty old.
Alis_Klar Posted October 10, 2007 Author Posted October 10, 2007 Sorry Actually running 3.3r5. Will try those logs thanks Geoff. @Geoff:Do you think i'm on the right track here in suspecting crontab?
Geoff Posted October 10, 2007 Posted October 10, 2007 It's the only thing on the box that could affect things so regularly. The only other possibility is something external.
Alis_Klar Posted October 10, 2007 Author Posted October 10, 2007 Hi, There doesn't seem to be anything fishy here. The internet access is affected at 28 and 58 past the hour. Oct 10 12:25:01 censornet /USR/SBIN/CRON[21029]: (root) CMD (/usr/local/sbin/process_web_logs.pl /usr/local/squid/logs/access$ Oct 10 12:25:01 censornet /USR/SBIN/CRON[21031]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/m$ Oct 10 12:25:04 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 12:25:04 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 12:30:01 censornet /USR/SBIN/CRON[25246]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/m$ Oct 10 12:30:01 censornet /USR/SBIN/CRON[25247]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 12:30:03 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 12:30:03 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 12:35:01 censornet /USR/SBIN/CRON[6367]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 12:35:01 censornet /USR/SBIN/CRON[6369]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/mr$ Oct 10 12:35:02 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 12:35:02 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 12:35:46 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 12:35:46 censornet kernel: br0: topology change detected, propgating Oct 10 12:36:03 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 12:36:03 censornet kernel: br0: topology change detected, propgating Oct 10 12:36:45 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 12:36:45 censornet kernel: br0: topology change detected, propgating Oct 10 12:36:49 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 12:36:49 censornet kernel: br0: topology change detected, propgating Oct 10 12:37:20 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 12:37:20 censornet kernel: br0: topology change detected, propgating Oct 10 12:38:01 censornet /USR/SBIN/CRON[14306]: (root) CMD (/usr/local/sbin/process_denied_logs.pl /var/log/dansguardian/acc$ Oct 10 12:40:01 censornet /USR/SBIN/CRON[19287]: (root) CMD (/usr/local/sbin/process_web_logs.pl /usr/local/squid/logs/access$ Oct 10 12:40:01 censornet /USR/SBIN/CRON[19288]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 12:40:01 censornet /USR/SBIN/CRON[19290]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/m$ Oct 10 12:40:02 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 12:40:02 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 12:45:01 censornet /USR/SBIN/CRON[31357]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 12:45:01 censornet /USR/SBIN/CRON[31358]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/m$ Oct 10 12:45:04 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 12:45:04 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 12:50:01 censornet /USR/SBIN/CRON[12664]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/m$ Oct 10 12:50:01 censornet /USR/SBIN/CRON[12666]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 12:50:02 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 12:50:02 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 12:53:01 censornet /USR/SBIN/CRON[20424]: (root) CMD (/usr/local/sbin/process_denied_logs.pl /var/log/dansguardian/acc$ Oct 10 12:55:01 censornet /USR/SBIN/CRON[24408]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 12:55:01 censornet /USR/SBIN/CRON[24411]: (root) CMD (/usr/local/sbin/process_web_logs.pl /usr/local/squid/logs/access$ Oct 10 12:55:01 censornet /USR/SBIN/CRON[24413]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/m$ Oct 10 12:55:02 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 12:55:02 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:00:01 censornet /USR/SBIN/CRON[32216]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/m$ Oct 10 13:00:01 censornet /USR/SBIN/CRON[32217]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 13:00:04 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:00:04 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:05:01 censornet /USR/SBIN/CRON[10710]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 13:05:01 censornet /USR/SBIN/CRON[10714]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/m$ Oct 10 13:05:01 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:05:01 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:08:01 censornet /USR/SBIN/CRON[12563]: (root) CMD (/usr/local/sbin/process_denied_logs.pl /var/log/dansguardian/acc$ Oct 10 13:10:01 censornet /USR/SBIN/CRON[12964]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 13:10:01 censornet /USR/SBIN/CRON[12968]: (root) CMD (/usr/local/sbin/process_web_logs.pl /usr/local/squid/logs/access$ Oct 10 13:10:01 censornet /USR/SBIN/CRON[12970]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/m$ Oct 10 13:10:01 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:10:01 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:15:01 censornet /USR/SBIN/CRON[14975]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/m$ Oct 10 13:15:01 censornet /USR/SBIN/CRON[14976]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 13:15:03 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:15:03 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:20:01 censornet /USR/SBIN/CRON[21559]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 13:20:01 censornet /USR/SBIN/CRON[21562]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/m$ Oct 10 13:20:02 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:20:02 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:22:55 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:22:55 censornet kernel: br0: topology change detected, propgating Oct 10 13:23:01 censornet /USR/SBIN/CRON[28598]: (root) CMD (/usr/local/sbin/process_denied_logs.pl /var/log/dansguardian/acc$ Oct 10 13:23:02 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:23:02 censornet kernel: br0: topology change detected, propgatingOct 10 13:23:24 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:23:24 censornet kernel: br0: topology change detected, propgating Oct 10 13:23:29 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:23:29 censornet kernel: br0: topology change detected, propgating Oct 10 13:23:33 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:23:33 censornet kernel: br0: topology change detected, propgating Oct 10 13:23:50 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:23:50 censornet kernel: br0: topology change detected, propgating Oct 10 13:24:08 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:24:08 censornet kernel: br0: topology change detected, propgating Oct 10 13:24:20 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:24:20 censornet kernel: br0: topology change detected, propgating Oct 10 13:24:28 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:24:28 censornet kernel: br0: topology change detected, propgating Oct 10 13:24:37 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:24:37 censornet kernel: br0: topology change detected, propgating Oct 10 13:25:01 censornet /USR/SBIN/CRON[1169]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 13:25:01 censornet /USR/SBIN/CRON[1171]: (root) CMD (/usr/local/sbin/process_web_logs.pl /usr/local/squid/logs/access.$ Oct 10 13:25:02 censornet /USR/SBIN/CRON[1189]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/Oct 10 13:25:03 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:25:03 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:25:21 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:25:21 censornet kernel: br0: topology change detected, propgating Oct 10 13:25:28 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:25:28 censornet kernel: br0: topology change detected, propgating Oct 10 13:25:42 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:25:42 censornet kernel: br0: topology change detected, propgating Oct 10 13:26:22 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:26:22 censornet kernel: br0: topology change detected, propgating Oct 10 13:27:35 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:27:35 censornet kernel: br0: topology change detected, propgating Oct 10 13:27:36 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:27:36 censornet kernel: br0: topology change detected, propgating Oct 10 13:28:09 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:28:09 censornet kernel: br0: topology change detected, propgating Oct 10 13:29:51 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:29:51 censornet kernel: br0: topology change detected, propgating Oct 10 13:29:52 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:29:52 censornet kernel: br0: topology change detected, propgating Oct 10 13:30:01 censornet /USR/SBIN/CRON[9802]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/mr$ Oct 10 13:30:01 censornet /USR/SBIN/CRON[9803]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 13:30:04 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:30:04 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:30:12 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:30:12 censornet kernel: br0: topology change detected, propgating Oct 10 13:31:54 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:31:54 censornet kernel: br0: topology change detected, propgating Oct 10 13:33:00 censornet kernel: br0: received tcn bpdu on port 1(eth0) Oct 10 13:33:00 censornet kernel: br0: topology change detected, propgating Oct 10 13:33:57 censornet su_exec[19781]: connect from localhost Oct 10 13:34:00 censornet dansguardian: Error connecting to proxy Oct 10 13:34:00 censornet last message repeated 8 times Oct 10 13:35:01 censornet /USR/SBIN/CRON[22544]: (root) CMD (/usr/local/sbin/update_access_rules >/dev/null 2>/dev/null) Oct 10 13:35:01 censornet /USR/SBIN/CRON[22548]: (root) CMD (if [ -x /usr/bin/mrtg ] && [ -r /etc/mrtg.cfg ]; then /usr/bin/m$ Oct 10 13:35:02 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:35:02 censornet ucd-snmp[438]: Connection from 127.0.0.1 Oct 10 13:38:01 censornet /USR/SBIN/CRON[31383]: (root) CMD (/usr/local/sbin/process_denied_logs.pl /var/log/dansguardian/acc$ This pattern is pretty much repeated over and over. Sorry to post long log but I wanted to show an hour of logging. Any help is greatfully received!
Alis_Klar Posted May 19, 2008 Author Posted May 19, 2008 Hi, Just spotted this and thought it would be polite to let ppl know how this was fixed. .....Well not fixed as such. This Censornet points to our LA's proxy filter. We added the censornet to add some local granularity for us locally. The LA were using an iMimic platform. When they switched over to Squidcache and Webwasher the problem disappeared!!!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now