Yesterday at lunchtime there were some issues on our network.
I’ll try to explain what happened in simple terms and also explain what we are going to do to avoid this type of issue arising in the future.
If anyone has any queries about the explanation please feel free to ask via comments or email us directly.
Timeline: 13:55 – 14:18
Affected Customers: Any customer on the shared firewall that has a dedicated server or has colo with us was affected during this incident. This also included our shared hosting clients.
What happened?
At around 2pm yesterday afternoon a segment of our main network was sluggish and people would have experienced latency and packet loss.
Why?
As you may know our main network is firewalled. We have a pair of firewalls setup in HA (high availability) to protect the bulk of our clients, which includes all our shared hosting clients on both windows and linux, as well as a large number of clients on dedicated servers or with colocated machines.
Firewalls are basically computers. Depending on how much money you want to spend on them you get different capabilities. While our firewalls are perfectly adequate under most conditions they have limits.
When a server behind the firewall was compromised and started pumping out large amounts of traffic the firewalls were pushed to capacity. While the network was up at all times it would have been slow and unresponsive until our engineering team were able to take action.
What action was taken?
The server that had been compromised was disconnected from the network until the issue had been resolved / removed.
How can we avoid this in the future?
We had been planning to upgrade the firewalls in any case, this is now being moved forward. The new firewalls will be able to carry larger amounts of traffic so this kind of issue will have a lower impact should it arise again.
For the last few months we have also been actively encouraging clients to opt for their own firewall(s).
And now for the more detailed breakdown:
Outage Information with Timeline of Events
13:53 C program downloaded onto a customer’s machine via a hole in their
programming code.
13:55 Code compiled and executed. A result of this was 80mbit/s of
additional traffic heading towards the shared firewall service during peak lunch time traffic.
14:05 Our engineering team noticed latency of SSH and terminal services connections to machines on the network behind the firewall were laggy or intermittent.
14:06 Senior onsite engineers begin to investigate the issue.
14:08 One of our external traffic links was carrying approx 50mbit/s more
traffic than normal (some traffic from the affected host never made it past the firewalls) and they begin to check access switches for which equipment cabinet has the infected host.
14:15 The host responsible for this increase in traffic was identified and
their switch port was shutdown by a network engineer.
14:16 Services begin to return to normal and the load on the firewalls CPU
drops back to acceptable limits.
14:18 All services are back to normal
Incident Report – Tuesday September 11 2007
By Michele Neylon on September 12, 2007 in Blacknight, Hosting, irishblogs, network, Programming, redundancy, security
About Michele Neylon
Known for his outspoken opinions on technology and the Internet, Michele Neylon is the award winning author of several blogs and co-host of the Technology.ie podcast. A thought leader in the Internet community, Neylon is active with ICANN and an expert on policy, security, ICANN, Nominet and Internet Governance.Connect With Us
-
Daniel: check this => http://orderdept.com/?d=gonzalez....
- Go mobi: [...] may we congratulate Michele Neylon on his ...
-
Michele Neylon: Alan It's a Facebook competition not a Twitter...
-
Alan Charnock: What if your not on facebook can you give me an op...
-
Gary Ewan Park: Congratulations! Well deserved!...
-
Daniel: There is quite a lot of Plugins for Wordpress that...
-
XXX Goes Live and This Is How We Push It
December 6, 2011
-
We’ve Moved .. And We’d Love Your Feedback
November 29, 2011
-
New TLD Application Window Opens Tomorrow What Does It Mean?
January 11, 2012
-
No Fluff Cloud Hosting Is Here
November 16, 2011
-
Blacknight Does Not Support SOPA
December 27, 2011
-
Think Of The Hungry Dragons And Get Mobile
January 30, 2012
-
Say It With Flowers .. Or Maybe A Domain?
February 10, 2012
-
Blacknight Leads the Irish Market for the Third Year in a Row
February 8, 2012
-
Want To Win An Xbox 360 + Xbox Live Gold Membership?
February 6, 2012
-
Security Issues
February 2, 2012
-
Calm Reasoned Dialogue Helps
February 1, 2012
-
Think Of The Hungry Dragons And Get Mobile
January 30, 2012
Recent Posts
- Say It With Flowers .. Or Maybe A Domain?
- Blacknight Leads the Irish Market for the Third Year in a Row
- Want To Win An Xbox 360 + Xbox Live Gold Membership?
- Security Issues
- Calm Reasoned Dialogue Helps
- Think Of The Hungry Dragons And Get Mobile
- Anonymous Targets Irish Government Sites In Response To “Irish SOPA”
- Say No To An Irish SOPA Style Law Say Yes To Democracy
- Happy new year again
- Use Zemanta To Improve Your Blogging
Tags
awards
blacknight
blog
blogging
business
cctlds
christmas
competition
design
discounts
dns
Domain name
Domain name registry
domains
dublin
email
eurid
events
facebook
Generic top-level domain
google
hosting
icann
iedr
iia
iPhone
IPv6
ireland
irish
linux
maintenance
marketing
Microsoft
network
offers
open source
promotions
security
Social media
special offers
technical support
Top-level domain
Twitter
vps
wordpress
Cool Sites
Unofficial Blacknight Blogs
Blacknight Sites
The Technology.ie Feed
- Keyboard Warriors [Podcast #16] February 9, 2012
- Win an Xbox 360 From Blacknight February 6, 2012
- Martha Rotter and Stewart Curry from Idea Magazine [Tech Heroes Podcast #2] January 31, 2012
- An Irish SOPA to an Irish Problem [Podcast #15] January 26, 2012
[X] CLOSE
Categories
- aftermarket (4)
- Blacknight (375)
- Blogging (52)
- business (29)
- Careers (11)
- Charity (3)
- Competitions (20)
- Domains (338)
- ecommerce (21)
- Email (34)
- spam filtering (7)
- Events (187)
- BarCampBelfast (3)
- Feedback (7)
- General (15)
- Hosting (219)
- Cloud Hosting (3)
- Ipv6 (14)
- network (40)
- redundancy (18)
- Service Issue (10)
- vps (17)
- howto (5)
- humour (9)
- irishblogs (268)
- IrishISPTest (1)
- Legal Issues (4)
- localisation (1)
- Maintenance (32)
- Marketing (126)
- mobile (1)
- monetisation (8)
- mysql (1)
- News (158)
- Podcasting (17)
- policy (18)
- Press Releases (24)
- Programming (33)
- ajax (2)
- asp.net (7)
- php (5)
- Ruby on Rails (1)
- Promotions (71)
- security (37)
- Seo (13)
- Tips (114)
- video (5)
- w3c (2)
- WordPress (1)
Monthly Archives
- February 2012 (5)
- January 2012 (12)
- December 2011 (9)
- November 2011 (9)
- October 2011 (7)
- September 2011 (11)
- August 2011 (6)
- July 2011 (7)
- June 2011 (8)
- May 2011 (8)
- April 2011 (10)
- March 2011 (6)
- February 2011 (6)
- January 2011 (8)
- December 2010 (7)
- November 2010 (6)
- October 2010 (9)
- September 2010 (9)
- August 2010 (10)
- July 2010 (9)
- June 2010 (5)
- May 2010 (10)
- April 2010 (13)
- March 2010 (14)
- February 2010 (14)
- January 2010 (11)
- December 2009 (17)
- November 2009 (7)
- October 2009 (9)
- September 2009 (20)
- August 2009 (12)
- July 2009 (14)
- June 2009 (8)
- May 2009 (21)
- April 2009 (12)
- March 2009 (19)
- February 2009 (12)
- January 2009 (21)
- December 2008 (24)
- November 2008 (18)
- October 2008 (18)
- September 2008 (22)
- August 2008 (27)
- July 2008 (19)
- June 2008 (10)
- May 2008 (13)
- April 2008 (15)
- March 2008 (16)
- February 2008 (22)
- January 2008 (17)
- December 2007 (16)
- November 2007 (28)
- October 2007 (15)
- September 2007 (31)
- August 2007 (23)
- July 2007 (18)
- June 2007 (7)
- May 2007 (4)
- April 2007 (9)
- March 2007 (8)
- February 2007 (10)
- January 2007 (8)
- December 2006 (3)
- November 2006 (4)
- October 2006 (7)
- September 2006 (5)
- August 2006 (4)
- July 2006 (5)
- June 2006 (5)
- May 2006 (7)
- April 2006 (7)
- March 2006 (13)









Comments are closed.