cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
419
Views
0
Helpful
1
Replies

lost connectivity, malicious??

laamidd2003
Level 1
Level 1

From the logging buffer. Can someone please help me understand what happened here. The server wasn't pingable and the message (windows 2003 server) was "network cable unplugged"

2008 May 07 03:58:16 %SPANTREE-6-PORTFWD: Port 6/10 state in VLAN 200 changed to forwarding

2008 May 07 05:32:44 %MGMT-6-LOGINPASS:User logged in from 10.33.106.1 via Telnet

2008 May 07 05:32:48 %MGMT-6-ENABLEPASS:User entered enable mode from 10.33.106.1 via Telnet

2008 May 07 05:37:33 %MGMT-6-LOGINPASS:User logged in from 10.33.106.1 via Telnet

2008 May 07 05:37:37 %MGMT-6-ENABLEPASS:User entered enable mode from 10.33.106.1 via Telnet

2008 May 07 06:36:39 %MGMT-6-LOGINPASS:User logged in from 10.33.106.1 via Telnet

2008 May 07 06:36:50 %MGMT-6-ENABLEPASS:User entered enable mode from 10.33.106.1 via Telnet

2008 May 07 09:40:48 %MGMT-6-LOGINPASS:User logged in from 10.33.50.1 via Telnet

2008 May 07 09:41:04 %MGMT-6-ENABLEPASS:User entered enable mode from 10.33.50.1 via Telnet

2008 May 07 11:17:56 %MGMT-6-LOGINPASS:User logged in from 10.6.190.101 via Telnet

2008 May 07 11:18:06 %MGMT-6-ENABLEPASS:User entered enable mode from 10.6.190.101 via Telnet

2008 May 07 20:43:02 %SNMP-5-LINKTRAP:Link Down Trap -- ifName=6/10

2008 May 07 20:43:02 %PAGP-5-PORTFROMSTP:Port 6/10 left bridge port 6/10

2008 May 07 20:43:02 %SNMP-5-NEWROOTTRAP:New Root Trap for Vlan [200]

2008 May 07 20:46:18 %SNMP-5-LINKTRAP:Link Up Trap -- ifName=6/10

2008 May 07 20:46:21 %SNMP-5-LINKTRAP:Link Down Trap -- ifName=6/10

2008 May 07 20:46:22 %SNMP-5-LINKTRAP:Link Up Trap -- ifName=6/10

2008 May 07 20:46:37 %PAGP-5-PORTTOSTP:Port 6/10 joined bridge port 6/10

2008 May 07 20:46:38 %SPANTREE-6-PORTFWD: Port 6/10 state in VLAN 200 changed to forwarding

2008 May 07 20:52:25 %MGMT-6-LOGINPASS:User logged in from 10.6.172.67 via Telnet

When it became pingable, this is the logging buffer:

2008 May 07 21:50:26 %SNMP-5-NEWROOTTRAP:New Root Trap for Vlan [200]

2008 May 07 21:50:54 %SNMP-5-LINKTRAP:Link Up Trap -- ifName=6/10

2008 May 07 21:51:09 %PAGP-5-PORTTOSTP:Port 6/10 joined bridge port 6/10

2008 May 07 21:51:10 %SPANTREE-6-PORTFWD: Port 6/10 state in VLAN 200 changed to forwarding

Any help would be greatly appreciated. Thanks,

Bob

1 Reply 1

w-schultz
Level 1
Level 1

By looking at the times I would have to say non-malicious. The last time someone logged in was 11:18:06 and your link did not go down until 20:43:02.

Suppose anything is possible however. Are you 100% sure the server did not reboot or is there a duplex mismatch?

There is a Windows command 'net statistics server' that will tell you when it started collecting stats, which is the last time it rebooted.

Good luck!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: