Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 6 of 6
  1. #1
    Member
    Join Date
    Oct 2006
    Posts
    20

    Default LogWatch : kernel error question

    Well, just got my latest logwatch email and found the following :

    --------------------- Kernel Begin ------------------------

    WARNING: Kernel Errors Present
    xxx.xxx.xxx.xxx sent an invalid ICMP type 11, code 1 error to a broadcast: ...: 1Time(s)

    ---------------------- Kernel End -------------------------


    Aside from the normal incorrect SSH attempts to login I have never seen something mentioned for the kernel before. Can anyone explain what exactly this error shows and should I be concerned?

  2. #2
    cPanel Partner NOC cPanel Partner NOC Badge AndyReed's Avatar
    Join Date
    May 2004
    Location
    Minneapolis, MN
    Posts
    2,223

    Default

    Quote Originally Posted by morrow95
    xxx.xxx.xxx.xxx sent an invalid ICMP type 11, code 1 error to a broadcast: ...: 1Time(s)
    This message means that somebody is pinging your server by crafting these ICMP 11 packets. Not to worry much about these messages, and just in case, you can install APF/BFD to stop further attacks on your server.
    Andy Reed
    RHCE and CCNA
    ServerTune.com

  3. #3
    Member
    Join Date
    Oct 2006
    Posts
    20

    Default

    Thanks Andy for the quick response. I just changed to a new server and all the 'support' of the server is on my hands unlike before so its a good learning process for me right now.

    As far as the brute force attempts I removed shell access to all users except root and enabled ssh keys required for login. This has dramatically cut down on bf attempts, however, I see people are still trying to connect just now it only shows the name because they do not have the chance to enter a password.

    I have looked into BFD, but at least to me it sounds that down the road (as more IP's were banned) you might start banning legitimate people from accessing your websites. Is this correct thinking?

  4. #4
    Member verdon's Avatar
    Join Date
    Nov 2003
    Location
    Northern Ontario, Canada
    Posts
    792

    Default

    No, BFD purges itself occasionally.

    As an alternate to APF/BFD, you might want to look at CSF. Config Server Firewall is a nice package put together by chirpy from these forums and configserver.com. I used APF/BFD for quite a while but have now been using CSF since it was first in beta.

  5. #5
    Member
    Join Date
    Oct 2006
    Posts
    20

    Default

    Just installed CSF after reading it is pretty popular with everyone. Ran through the security check and have a 59/64 with basically the only things I'm warned about dealing with php (not really important for me since I am the ONLY person with accounts on this dedicated).

    Really easy to setup. I also changed the default ssh port and removed ssh1 and only use 2 now.

    Are there any other little tips you would recommend I setup in CSF settings? So far, the only thing I might change down the road is the email alerts everytime a failed login occurs, BUT since I changed the port that might not happen as much anymore.

    Question for you though, say someone DOES find what port I changed SSH to and tries to brute in again... wouldn't this trip my sent out email flood interval for the hour?

  6. #6
    Member verdon's Avatar
    Join Date
    Nov 2003
    Location
    Northern Ontario, Canada
    Posts
    792

    Default

    Try this thread for CSF support.

    http://forums.cpanel.net/showthread.php?t=53511

Similar Threads & Tags
Similar threads

  1. kernel error in Logwatch
    By domini in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 09-24-2009, 02:32 PM
  2. Logwatch reports kernel error
    By elialum in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 09-22-2008, 09:22 AM
  3. Kernel messages in logwatch
    By benito in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 02-20-2007, 06:55 AM
  4. logwatch kernel errors ???
    By sh4ka in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 05-06-2006, 04:37 AM
  5. Logwatch Kernel error:
    By ncconquer in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 11-09-2005, 08:38 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube