JBoss Community

Suspicious multicast flood by one of the App servers

created by Dani Petrov in JBoss Cache - View the full discussion

Good day everyone!

 

This is my first post here and I really hope it won't violate any rules of the community.

 

I am newbie with JBoss, not familiar with it at all if I have to be honest... The story is that I am part of the networking engineering team and along with colleagues from development department facing very serious issue. We did some researches, gathered quite alot of data using wireshark software and fortunately we found some patern that could be a root couse of the problem. First I'll try to explain the topology:

 

We have 2 web servers and 4 app servers. They are all connected to three network switches. JGroup is configured with UDP & Multicast. We are using the 228.1.2.13 group for that purpose. What we observed during the time of crashes, one of the application servers is flooding the network with traffic destined to the JGroup (228.1.2.13) with speed of more than 100mbps (please see the attached pictures)

 

https://community.jboss.org/servlet/JiveServlet/downloadImage/2-743625-18829/450-261/1%255Ftshark%255FLIVE%255F00001%255F20120614084729.cap.jpg https://community.jboss.org/servlet/JiveServlet/downloadImage/2-743625-18830/450-261/2.jpg https://community.jboss.org/servlet/JiveServlet/downloadImage/2-743625-18831/450-261/3.jpg https://community.jboss.org/servlet/JiveServlet/downloadImage/2-743625-18833/450-261/4.jpg

As soon as this flood appears, some of application servers crashes and all the users attached to it lost connectivity :( Does anyone else have experienced something like that? What could cause the app server to flood the group with such huge data & speed?

 

Any thoughts are more than welcome!

Reply to this message by going to Community

Start a new discussion in JBoss Cache at Community