For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

maximillean_953's avatar
maximillean_953
Icon for Nimbostratus rankNimbostratus
Jul 25, 2014

Snat Pool with 30 ips still getting inet port exhaustion when i am %100 sure that there is no exhaustion??

Hi,

I have snat pool with 30 ips which binded to 10 mysql vservers. I am %100 sure that ports are not eaxhauested cause there is non that much new or active conn action happens. ALso on vservers setting is port preserv which writes on help that if preserved port is in it will change to another port on snat pool. So how come i can still get inet port exhaustion error on the logs?

Jul 25 04:10:25 05 crit tmm7[9744]: 01010201:2: Inet port exhaustion on 10.35.78.23 to 10.35.8.4:3306 (proto 6)
Jul 25 04:16:35 05 crit tmm5[9744]: 01010201:2: Inet port exhaustion on 10.35.78.24 to 10.35.7.5:3306 (proto 6)
Jul 25 04:38:42 05 crit tmm7[9744]: 01010201:2: Inet port exhaustion on 10.35.78.71 to 10.35.71.6:3306 (proto 6)
Jul 25 07:17:27 05 crit tmm4[9744]: 01010201:2: Inet port exhaustion on 10.35.78.28 to 10.35.71.5:3306 (proto 6)
Jul 25 08:28:12 05 crit tmm4[9744]: 01010201:2: Inet port exhaustion on 10.35.78.19 to 10.35.71.4:3306 (proto 6)
Jul 25 11:52:41 05 crit tmm4[9744]: 01010201:2: Inet port exhaustion on 10.35.78.11 to 10.35.71.3:3306 (proto 6)
Jul 25 12:11:54 05 crit tmm7[9744]: 01010201:2: Inet port exhaustion on 10.35.78.13 to 10.35.71.2:3306 (proto 6)
Jul 25 13:02:44 05 crit tmm1[9744]: 01010201:2: Inet port exhaustion on 10.35.78.15 to 10.35.71.1:3306 (proto 6)

1 Reply

  • i would check also what other traffic mysql servers are generating. If you get that error it's because indeed you have that problem.

     

    May be running a wireshark/tcpdump one of those servers and look for suspicious traffic, like communications to another IP using broad range of ports.

     

    good luck. hheredia