Re: [j-nsp] DOS Attack

2010-08-04 Thread sherif mostafa




 
Dear Florian,
 
This ERX, Administration of router interface 0018.742f.b380 belongs to me also, 
but should I filter all those packet types ??
 
 
 
 To: sherifmka2...@hotmail.com
 CC: juniper-nsp@puck.nether.net
 Subject: Re: [j-nsp] DOS Attack
 From: fwei...@bfk.de
 Date: Wed, 4 Aug 2010 13:27:05 +
 
 * sherif mostafa:
 
  Could anyone help please as I've faced an error message DOS below
  that caused high CPU usage:
 
  ERROR 08/02/2010 16:22:46 CAI dosProtection: Flow is suspicious:
  GigabitEthernet11/0.410 for control protocol: IP TTL Expired source MAC
  0018.742f.b380 with rate 241 pps
 
 Have you checked that you haven't got a routing loop or something like
 that? (And which platform is that, BTW?)
 
 If this isn't the case, you need to figure out who's got the
 0018.742f.b380 MAC address and ask them to stop sending those packets.
 
 -- 
 Florian Weimer fwei...@bfk.de
 BFK edv-consulting GmbH http://www.bfk.de/
 Kriegsstraße 100 tel: +49-721-96201-1
 D-76133 Karlsruhe fax: +49-721-96201-99
  
___
juniper-nsp mailing list juniper-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/juniper-nsp


[j-nsp] DOS Attack

2010-08-03 Thread sherif mostafa

Dears,
 
Could anyone help please as I've faced an error message DOS  below that 
caused high CPU usage:
 
 
ERROR 08/02/2010 16:22:46 CAI dosProtection: Flow is suspicious:
GigabitEthernet11/0.410 for control protocol: IP TTL Expired source MAC
0018.742f.b380 with rate 241 pps
ERROR 08/02/2010 16:24:11 CAI dosProtection: Flow is suspicious:
GigabitEthernet11/0.410 for control protocol: IP TTL Expired source MAC
0018.742f.b380 with rate 11 pps
ERROR 08/02/2010 16:24:38 CAI dosProtection: Flow is suspicious:
GigabitEthernet11/0.410 for control protocol: IP TTL Expired source MAC
0018.742f.b380 with rate 10 pps
ERROR 08/02/2010 16:24:59 CAI dosProtection: Flow is suspicious:
GigabitEthernet11/0.410 for control protocol: IP TTL Expired source MAC
0018.742f.b380 with rate 10 pps
ERROR 08/02/2010 16:26:57 CAI dosProtection: Flow is suspicious:
GigabitEthernet11/0.410 for control protocol: IP TTL Expired source MAC
0018.742f.b380 with rate 20 pps 


  
___
juniper-nsp mailing list juniper-nsp@puck.nether.net
https://puck.nether.net/mailman/listinfo/juniper-nsp