G'day all,
I started using E-Smith around version 3 and have kept up-to-date over the years. Well, except for one box (which was a 5.5 box and some lovely person got root. That'll teach me to be slack!)
I reinstalled the compromised box (with a new, clean hard drive - I wanted to do some forensics and catch the little star bard that took me down in the first place) with SME 6.0.
I then wen along the long, arduous process of adding all of the usual tools, antivirus, dialin, hylafax, etc.
It wasn't long before I noticed that the server was unusable in its new form - and that it was swapping to buggery. RAM upgrades solved that, of course.
But a new problem reared its ugly head - and it has been getting worse. Periodically the internet access falls over and won't respond to even the most violent of kicks.
When this happens, Web access is impossible & DNS lookups fail, meanwhile internal mail works perfectly - and external mail is received okay.
The queer thing; to get it "happy" again is not a consistent thing. Sometimes restarting tinydns will get it back in action. Sometimes restarting dnscache is the key. Sometimes it's ipmasq, sometimes its squid, sometimes it requires a reboot! (When rebooting, I always reset the ADSL modem to get a new IP address - dynamic IP).
To make matters worse, when these problems occur, SSH slows down to a crawl (takes 30-90 seconds for a "password" prompt to appear after giving the username of root.) Sometimes SSH connections are even refused! After the last little darling, I'm extremely paranoid that there might be an intruder.
(Unfortunately, after the SME6.0 acted up, I wanted to have a "bare minimum install," so didn't re-install Snort and Acid. As such, I've only got a string of rather large Deny logs to wade through!)
If one of these solutions was consistent, at least I'd have something to start looking at.
Thinking that something went screwy with the add-ons, I backed up my data, re-installed (from scratch) with a vanilla install. Seemed okay for a while, then the same problems appeared.
Getting really irked by this time, I then used the 6.01-custom ISO (which is great!) and replaced the entire box. (All new hardware). Same problem - even with all updates installed via YUM later.
I've searched the forums with no joy; I've googled with no joy. (Assuming my choice of keywords is okay - hard to know what to search for with such stupid symptoms.)
Has anyone had similar problems? Any suggestions for places to start looking?
I'm getting utterly frustrated to the point that I'm considering migrating my gateway to Debian or OpenBSD... I don't want to stop using SME - I've been an advocate for too long!
Thanks in advance for any advice.
Cheers,
Ant
Current hardware:
AMD Athlon 2000+ XP
RAM: 512Mb
Ethernet 1: Realtek 8139
Ethernet 2: Realtek 8139
Modem: Alcatel SpeedTouch Pro (not USB! - uses PPPoA, not requiring any special configs on SME)