CAIQUM-5933: AIQUM server unresponsive due to vulnerability scanners
Issue
- Active IQ Unified Manager (AIQUM) becoming unresponsive after vulnerability scans
- On Windows, OpenJDK Platform Binary process exhibits high CPU usage
- On VMware virtual appliance and Linux,
journalctl.loghas multiple entries ofRate limit exceededfrom one or more sources:
ocum kernel: Rate limit exceeded: IN=eth0 OUT= MAC=<YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY> SRC=XX.XX.XX.XX DST=<AIQUM_IP> LEN=52 TOS=0x02 PREC=0x00 TTL=126 ID=9520 DF PROTO=TCP SPT=52199 DPT=443 WINDOW=8192 RES=0x00 CWR ECE SYN URGP=0
ocum kernel: Rate limit exceeded: IN=eth0 OUT= MAC=<YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY:YY> SRC=XX.XX.XX.XX DST=<AIQUM_IP> LEN=52 TOS=0x02 PREC=0x00 TTL=126 ID=9591 DF PROTO=TCP SPT=52206 DPT=443 WINDOW=8192 RES=0x00 CWR ECE SYN URGP=0- Acquisition towards clusters might fail over time and stability issues from Jboss (web engine) are seen
Note: Even in environments where vulnerability scanners are not used, similar access patterns can cause this issue.
