With all due respect Farhan, If he uses "debug ip packet detail" on a
production router, he WON'T be haveing a very nice day. Good way to crash
the router.
A better way is setup flow cache.
(config-if) ip route-cache flow
# show ip cache flow
This will show you source and dest. pair, and the ports you looking for.
Tony M.
(Can't sleep)
----- Original Message -----
From: "Farhan Ahmed"
To:
Sent: Friday, August 24, 2001 11:12 PM
Subject: RE: Unable to detect source for attack [7:17095]
> command
>
> debug ip packet detail
>
> Best Regards
>
> Have A Good Day!!
>
> *******************************************
> Farhan Ahmed*
> MCSE+I, MCP Win2k, CCDA, CCNA, CSE
> Network Engineer
> Mideast Data Systems Abudhabi Uae.
>
> *******************************************
>
>
>
> Privileged/Confidential Information may be contained in this message or
> Attachments hereto. Please advise immediately if you or your employer do
> not consent to Internet email for messages of this kind. Opinions,
> Conclusions and other information in this message that do not relate to
the
> Official business of this company shall be understood as neither given nor
> Endorsed by it.
>
>
> > -----Original Message-----
> > From: suaveguru [mailto:[EMAIL PROTECTED]]
> > Sent: Friday, August 24, 2001 9:54 AM
> > To: [EMAIL PROTECTED]
> > Subject: Unable to detect source for attack [7:17095]
> >
> >
> > hi all,
> >
> > I am not able to detect the type of an ip attack on an
> > interface . All I can detect is the source and
> > destination ip addresees using ip accounting but I
> > could not block the ip addresses because they are all
> > in use . All I can do is to find out what kind of
> > traffic is causing the attack for e.g. tcp, udp , sync
> > etc. but what tools could I use?
> >
> >
> > regards,
> > suaveguru
> >
> > __________________________________________________
> > Do You Yahoo!?
> > Make international calls for as low as $.04/minute with
> > Yahoo! Messenger
> > http://phonecard.yahoo.com/
>
> [GroupStudy.com removed an attachment of type application/octet-stream
which
> had a name of Farhan Ahmed.vcf]
Message Posted at:
http://www.groupstudy.com/form/read.php?f=7&i=17232&t=17095
--------------------------------------------------
FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html
Report misconduct and Nondisclosure violations to [EMAIL PROTECTED]