Forum Discussion
BigIP F5 ( LC , LTM) WAS CRASH
Hi all
I'm new F5 , at the moment, my F5 was crash after running 2 days . I can not access the F5 via interface management and led status is yellow flicker
I didn't know why .
Pls help me , find reason and how find it ?
thanks all
- nitass
Employee
i think you had better open a support case and submit qkview. - hung_105573
Nimbostratus
Hi all
after my F5 crashed , i saw log and saw there are alot of user try ssh access my F5 , and i saw user root access in my F5 and after F5 shutting down half on behalf of root at time 3.50 (you would like see attached file picture)
pls help me , who is attacking to My F5 ?
thanks all
- What_Lies_Bene1
Cirrostratus
If you think you are under attack via SSH you could a) Restrict SSH access to specific IP addresses, b) change the external Self-IP(s) Port Lockdown setting to Allow None, c) change the root user password and d) disable SSH access for the root user - hoolio
Cirrostratus
Hi Hung, - hung_105573
Nimbostratus
Hi all
As the information i had post ( you would like to see these are file attached) , you would like to tell me , does the my F5 have attack ? and who has login to my F5 by root account and it do exec command HALT to make my F5 hang .
pls help me
thanks all !
- hoolio
Cirrostratus
Hi Hung, - hung_105573
Nimbostratus
Posted By hoolio on 10/06/2012 09:00 AMI have irule for traffic outbound go to internet of users:
when LB_SELECTED {
the 118.69.221.x , 118.69.221.y , 222.255.64.z are member of defaul gateway pool.
the 118.69.222.x ,118.69.223.y,222.255.77.z are ip public avaible
this is irule apply under virtual server outbound 0.0.0.0/0.0.0.0
would you like to tell me with this irule then work fine ?
pls help me
thanks all
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com