Problems with services all of a sudden...

alturic

Member
Jan 14, 2013
10
0
1
cPanel Access Level
Root Administrator
Ok, so the server has been online (with literally 3 of my personal sites which 0 people know about) for a month now. Everything has been running great until I woke up to a spam of messages in my imap:

I got a bunch of these for named:

Notification: nameserver failed @ Mon Jan 14 05:37:45 2013. A restart was attempted automagically.
Service Check Method: [check command]
Number of Restart Attempts: 15
Service Check Raw Output:
named: call to rndc failed
Startup Log:
Starting named: [ OK ]
It doesn't actually restart the service though. Even doing it through the WHM front-end it doesn't restart.

I also have these for imap which doesn't make sense considering I'm getting my emails via IMAP still?:

Notification: imap failed @ Mon Jan 14 05:16:10 2013. A restart was attempted automagically.
Service Check Method: [socket connect]
Reason:
Timeout while trying to connect to service: Died at /usr/local/cpanel/Cpanel/TailWatch/ChkServd.pm line 734.
Number of Restart Attempts: 11

Syslog Messages:
Jan 14 05:10:28 srv13 dovecot: Dovecot v1.2.17 starting up (core dumps disabled)
Jan 14 05:10:27 srv13 dovecot: auth(default): Killed with signal 15 (by pid=325090 uid=0 code=kill)
Jan 14 05:10:27 srv13 dovecot: dovecot: Killed with signal 15 (by pid=325090 uid=0 code=kill)
and then finally cpsrvd:

Notification: cpsrvd failed @ Mon Jan 14 05:24:10 2013. A restart was attempted automagically.
Service Check Method: [socket connect]
Reason: Timeout while trying to connect to service: Died at /usr/local/cpanel/Cpanel/TailWatch/ChkServd.pm line 734.

Number of Restart Attempts: 12
Startup Log:
Waiting for cpsrvd,cpsrvd-ssl,whostmgrd,cpaneld,webmaild to shutdown ... not running.
Starting cpsrvd.
Using Native SSL support (stunnel not needed)
The server is "working" in terms of I can get into cPanel/WHM, I can pull up my domains, and apparently my IMAP is still receiving all these emails about these failures, so I didn't want to reboot the machine until I got a response here to see.
 

alturic

Member
Jan 14, 2013
10
0
1
cPanel Access Level
Root Administrator
Update: Ok, so the guys from the DC said that it appeared to be something (didn't say what) with my IPTable rules... I'm only using APF/BFD and I do get a ton of brute force attempts which means a lot of banned IP's, but I haven't touched anything with APF/BFD (and I never actually touch iptables) in well over a week...

They also said named WAS running (and showed me the output plus a test) and it was certainly responding even though WHM was showing it as down. As I said I know imap was running the whole time considering I was getting spammed with the service down emails.

So, when he got done and told me it was something with iptables, WHM was showing (and still is) named as up but cpdavd, imap, cpsrvd and spamd was showing as down. I did a reboot and they all now show as up, but "mailman" is now showing as down. Sometime it shows as up, sometimes it shows as down. No sites use a mailing list but it SHOULD always show as up, right?

So anyway, here's the latest emails from WHM for mailman:

FAILED:
Service Check Method: [check command]
Number of Restart Attempts: 1
Service Check Raw Output: mailmanctl is not running
Startup Log: Starting Mailman's master qrunner.
6 minutes later an email for RECOVERED:

Notification Type: recovered
Notification: mailman check was successful after restart.
Startup Log: Starting Mailman's master qrunner.
I'm just worried SOMETHING "happened" (I know no-one got into the server) considering for the past month nothing but smooth sailing and now all of a sudden these services are having "problems".