PDA

Просмотр полной версии : Странная авторизация между пиксом и сохой


Sir Arthur
13.12.2007, 21:56
соха в нижневартовске. пикса в мск.
на пиксе
13 IKE Peer: 80.251.55.58
Type : user Role : initiator
Rekey : no State : MM_WAIT_MSG2 рядом (там же стоит еще одна соха с таким же конфигом)
8 IKE Peer: 80.251.48.66
Type : L2L Role : initiator
Rekey : no State : MM_ACTIVE
вопрос почему типы разные?
с сохи
RGSN-Niznevartovsk2#sh cry isa sa
IPv4 Crypto ISAKMP SA
dst src state conn-id slot status
195.151.225.217 80.251.55.58 MM_NO_STATE 0 0 ACTIVE

IPv6 Crypto ISAKMP SA

с сохи на первой точке:

RGSN-Niznevartovsk#sh cry isa sa
IPv4 Crypto ISAKMP SA
dst src state conn-id slot status
80.251.48.66 195.151.225.217 QM_IDLE 1016 0 ACTIVE

IPv6 Crypto ISAKMP SA

RGSN-Niznevartovsk#

т.е как я понимаю авторизация не проходит - туннель не поднимается.
Дальше в логе сохи постоянно ругань на
Jul 26 07:25:10.811: %CDP-4-DUPLEX_MISMATCH: duplex mismatch discovered on FastEthernet4.1 (not full duplex), with Switch FastEthernet0/43 (full duplex).
*Jul 26 07:25:30.599: %CDP-4-DUPLEX_MISMATCH: duplex mismatch discovered on FastEthernet4.1 (not full duplex), with Router.nvds.ru FastEthernet0/0 (full duplex).
пробовал ставить на f4.1 и full и half - без результатно.
соха вокруг себя видит
sh cdp ne det
-------------------------
Device ID: SunBrew-Niznevartovsk
Entry address(es):
IP address: 80.251.48.74
Platform: cisco 1751, Capabilities: Router
Interface: FastEthernet4.1, Port ID (outgoing port): Ethernet0/0
Holdtime : 145 sec

Version :
Cisco Internetwork Operating System Software
IOS (tm) C1700 Software (C1700-K8SY7-M), Version 12.2(15)T9, RELEASE SOFTWARE (fc2)
TAC Support: http://www.cisco.com/tac
Copyright (c) 1986-2003 by cisco Systems, Inc.
Compiled Sat 01-Nov-03 06:24 by ccai

advertisement version: 2
Duplex: half
Power drawn: 4294967.294 Watts

-------------------------
Device ID: Router.nvds.ru
Entry address(es):
IP address: 80.251.55.24
Platform: Cisco 1841, Capabilities: Router Switch IGMP
Interface: FastEthernet4.1, Port ID (outgoing port): FastEthernet0/0
Holdtime : 163 sec

Version :
Cisco IOS Software, 1841 Software (C1841-IPBASE-M), Version 12.4(1c), RELEASE SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2005 by Cisco Systems, Inc.
Compiled Tue 25-Oct-05 17:10 by evmiller

advertisement version: 2
VTP Management Domain: ''
Duplex: full
Power drawn: 4294967.294 Watts

-------------------------
Device ID: Switch
Entry address(es):
IP address: 192.168.0.159
Platform: cisco WS-C2960-48TT-L, Capabilities: Switch IGMP
Interface: FastEthernet4.1, Port ID (outgoing port): FastEthernet0/43
Holdtime : 143 sec

Version :
Cisco IOS Software, C2960 Software (C2960-LANBASE-M), Version 12.2(25)FX, RELEASE SOFTWARE (fc1)
Copyright (c) 1986-2005 by Cisco Systems, Inc.
Compiled Wed 12-Oct-05 22:05 by yenanh

advertisement version: 2
Protocol Hello: OUI=0x00000C, Protocol ID=0x0112; payload len=27, value=00000000FFFFFFFF010231FF0000000000000014A949 7B00FF0000
VTP Management Domain: ''
Native VLAN: 1
Duplex: full
Power drawn: 4294967.294 Watts

-------------------------
Device ID: SEP001AA27AB6C9
Entry address(es):
IP address: 10.86.2.254
Platform: Cisco IP Phone 7912, Capabilities: Host
Interface: FastEthernet0, Port ID (outgoing port): Port 1
Holdtime : 173 sec

Version :
CP7912-v6-01-0-051208A

advertisement version: 2
Power drawn: 6.300 Watts

-------------------------
Device ID: c2514.nvnipi.ru
Entry address(es):
IP address: 80.251.48.68
Platform: cisco 2500, Capabilities: Router
Interface: FastEthernet4.1, Port ID (outgoing port): Ethernet1
Holdtime : 155 sec

Version :
Cisco Internetwork Operating System Software
IOS (tm) 2500 Software (C2500-IO-L), Version 12.0(15), RELEASE SOFTWARE (fc1)
Copyright (c) 1986-2000 by cisco Systems, Inc.
Compiled Thu 28-Dec-00 01:38 by linda

advertisement version: 1
Power drawn: 4294967.294 Watts

Админ из Нв говорит что на сохе визуально горят не переставая индикаторы Rx/TX - т.е что-то льется потоком. отключение в shut внутренних интерфесов результатов не дало. Индикация как была так и осталась.
собственно мртг подтверждает это.
статистка с интерфейса
63 packets input, 5349 bytes
2819 packets input, 236890 bytes
3635 packets input, 307545 bytes
5529 packets input, 459583 bytes

это примерно за 3-4 минуты после сброса счетчиков на интерфейсе
FastEthernet4 is up, line protocol is up
Hardware is PQUICC_FEC, address is 001a.e3b0.ef6d (bia 001a.e3b0.ef6d)
Description: WAN$FW_OUTSIDE$$ES_WAN$
MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation 802.1Q Virtual LAN, Vlan ID 1., loopback not set
Keepalive set (10 sec)
Full-duplex, 100Mb/s, 100BaseTX/FX
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:00, output hang never
Last clearing of "show interface" counters never
Input queue: 0/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 12000 bits/sec, 17 packets/sec
5 minute output rate 2000 bits/sec, 2 packets/sec
7580 packets input, 620534 bytes
Received 6089 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 watchdog
0 input packets with dribble condition detected
1453 packets output, 168313 bytes, 0 underruns
0 output errors, 0 collisions, 5 interface resets
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier
0 output buffer failures, 0 output buffers swapped out
выставил на кошке в акцесс листе deny ip any (кроме себя естественно) вроде стало полегче.
Вот и думаю чего это такое и что делать.
дебаг ip,tcp ничего подозрительного не показал
Скрин с мртг прилагаю

Slon
13.12.2007, 22:01
графики загрузки с проца сохи наманые ?? а то плохо ей imho

slim
13.12.2007, 22:34
1. а ты на Fa4 duplex full поставь
2. на wan броадкаст
3. cef свитчинг включен?
4. deb cry isa

Sir Arthur
13.12.2007, 23:52
1. а ты на Fa4 duplex full поставь
2. на wan броадкаст
3. cef свитчинг включен?
4. deb cry isa
ставил - ругается.
2 - не понял - можно подробнее?
3. ip cef? resource policy
!
ip subnet-zero
ip cef включен
4. Завтра - ибо админ в НВ боясь расхода трафика вырубил кошку.

slim
14.12.2007, 00:28
а софт на кошаках одинаковый?

2е, ну то что:
7580 packets input, 620534 bytes
Received 6089 broadcasts, 0 runts, 0 giants, 0 throttles

я бы на фа4 поставил:
no proxy-arp
no ip redirects
ip virtual-reassembly

не понял про шут интерфейса.. как это, через него трафик льеца? %)

по поводу дуплекса, если фул\авто выставить, неготиэйшн в обоих случаях есть? судя по тому, чтои получаешь мисмачи - есть.. :unsure:

посмотри еще sh proc cpu, sh proc mem, sh ip cef f4..

Sir Arthur
14.12.2007, 01:07
а софт на кошаках одинаковый?

2е, ну то что:


я бы на фа4 поставил:
no proxy-arp
no ip redirects
ip virtual-reassembly

не понял про шут интерфейса.. как это, через него трафик льеца? %)

по поводу дуплекса, если фул\авто выставить, неготиэйшн в обоих случаях есть? судя по тому, чтои получаешь мисмачи - есть.. :unsure:

посмотри еще sh proc cpu, sh proc mem, sh ip cef f4.. иосы с вероятностью 97% одинаковые 12.4 какие -нибудь.
трафик лился до того как интерфейс я в шатдаун послал - админ уж потом кошку выключил (я с ним по телефону общался).
Все остальное уже сегодня буду глядеть.
Но со слов админа там у всего что на данного провайдера завязаны начались траблы - типа загруженная сеть и т.д.
Это собственно на графике видно. НВ1 и НВ2 в одном здании у них адреса в одном сегменте 80.251.ххх.48 (НВ1) и 55 (НВ2)

Sir Arthur
14.12.2007, 01:15
Меня это смущает:
как кошка видит все это железо на одном порту?
sh cdp ne det
-------------------------
Device ID: SunBrew-Niznevartovsk
Entry address(es):
IP address: 80.251.48.74
Platform: cisco 1751, Capabilities: Router
Interface: FastEthernet4.1, Port ID (outgoing port): Ethernet0/0
Holdtime : 145 sec

-------------------------
Device ID: Router.nvds.ru
Entry address(es):
IP address: 80.251.55.24
Platform: Cisco 1841, Capabilities: Router Switch IGMP
Interface: FastEthernet4.1, Port ID (outgoing port): FastEthernet0/0
Holdtime : 163 sec

-------------------------
Device ID: Switch
Entry address(es):
IP address: 192.168.0.159
Platform: cisco WS-C2960-48TT-L, Capabilities: Switch IGMP
Interface: FastEthernet4.1, Port ID (outgoing port): FastEthernet0/43
Holdtime : 143 sec
-------------------------
Device ID: c2514.nvnipi.ru
Entry address(es):
IP address: 80.251.48.68
Platform: cisco 2500, Capabilities: Router
Interface: FastEthernet4.1, Port ID (outgoing port): Ethernet1
Holdtime : 155 sec

там только мой телефон 7912 на f0 засветился. все остальное - это провайдерское или еще хз чье.

slim
14.12.2007, 01:31
Меня это смущает:
как кошка видит все это железо на одном порту?

там только мой телефон 7912 на f0 засветился. все остальное - это провайдерское или еще хз чье.
ну все ето хозяйство воткнуто в какойнить недосвич.. ну или хаб..
с него и прут броадкасты..

Slon
14.12.2007, 11:52
хаб ...
потому чта недосвич отсёк бы cdp

Sir Arthur
14.12.2007, 12:26
syslog c кошки
Dec 14 12:23:15 10.86.2.129 2568: *Jul 26 10:32:49.167: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.14(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:23:18 10.86.2.129 2569: *Jul 26 10:32:51.915: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.45(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:23:20 10.86.2.129 2570: *Jul 26 10:32:54.011: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.55.15(0) -> 80.251.55.127(0), 1 packet
Dec 14 12:23:22 10.86.2.129 2571: *Jul 26 10:32:56.003: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.12(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:23:25 10.86.2.129 2572: *Jul 26 10:32:58.443: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.133(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:23:26 10.86.2.129 2573: *Jul 26 10:33:00.095: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.130(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:23:28 10.86.2.129 2574: *Jul 26 10:33:02.107: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.55.17(0) -> 80.251.55.63(0), 1 packet
Dec 14 12:23:31 10.86.2.129 2575: *Jul 26 10:33:04.811: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.20.2(0) -> 192.168.20.255(0), 1 packet
Dec 14 12:23:33 10.86.2.129 2576: *Jul 26 10:33:07.175: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.48(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:23:38 10.86.2.129 2577: *Jul 26 10:33:11.627: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.55.55(0) -> 80.251.55.127(0), 1 packet
Dec 14 12:23:39 10.86.2.129 2578: *Jul 26 10:33:13.107: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.21(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:23:43 10.86.2.129 2579: *Jul 26 10:33:16.763: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.205(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:23:46 10.86.2.129 2580: *Jul 26 10:33:19.571: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.133(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:23:50 10.86.2.129 2581: *Jul 26 10:33:23.507: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.135(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:23:54 10.86.2.129 2582: *Jul 26 10:33:28.183: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.14(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:23:55 10.86.2.129 2583: *Jul 26 10:33:29.267: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.47(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:23:59 10.86.2.129 2584: *Jul 26 10:33:32.403: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.130(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:01 10.86.2.129 2585: *Jul 26 10:33:34.495: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.48(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:01 10.86.2.129 2586: *Jul 26 10:33:34.907: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 185 packets
Dec 14 12:24:03 10.86.2.129 2587: *Jul 26 10:33:36.439: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.20.29(0) -> 192.168.20.255(0), 1 packet
Dec 14 12:24:05 10.86.2.129 2588: *Jul 26 10:33:38.563: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.31(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:09 10.86.2.129 2589: *Jul 26 10:33:43.323: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.15(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:11 10.86.2.129 2590: *Jul 26 10:33:44.995: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.141(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:12 10.86.2.129 2591: *Jul 26 10:33:46.191: %CDP-4-DUPLEX_MISMATCH: duplex mismatch discovered on FastEthernet4.1 (not half duplex), with SunBrew-Niznevartovsk Ethernet0/0 (half duplex).
Dec 14 12:24:16 10.86.2.129 2592: *Jul 26 10:33:49.403: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.205(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:19 10.86.2.129 2593: *Jul 26 10:33:52.851: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.225(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:20 10.86.2.129 2594: *Jul 26 10:33:53.911: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.130(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:23 10.86.2.129 2595: *Jul 26 10:33:57.187: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.41(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:25 10.86.2.129 2596: *Jul 26 10:33:58.819: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.38(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:26 10.86.2.129 2597: *Jul 26 10:34:00.335: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.57.222(0) -> 192.1.2.255(0), 1 packet
Dec 14 12:24:28 10.86.2.129 2598: *Jul 26 10:34:02.351: %SEC-6-IPACCESSLOGP: list Flood denied tcp 80.251.58.211(0) -> 80.251.55.58(0), 1 packet
Dec 14 12:24:30 10.86.2.129 2599: *Jul 26 10:34:03.511: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.48.76(0) -> 80.251.48.127(0), 1 packet
Dec 14 12:24:31 10.86.2.129 2600: *Jul 26 10:34:04.891: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.20.2(0) -> 192.168.20.255(0), 1 packet
Dec 14 12:24:34 10.86.2.129 2601: *Jul 26 10:34:07.443: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.45(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:35 10.86.2.129 2602: *Jul 26 10:34:09.207: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.48.83(0) -> 80.251.48.127(0), 1 packet
Dec 14 12:24:39 10.86.2.129 2603: *Jul 26 10:34:12.547: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.12(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:40 10.86.2.129 2604: *Jul 26 10:34:14.407: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.20.29(0) -> 192.168.20.255(0), 1 packet
Dec 14 12:24:47 10.86.2.129 2605: *Jul 26 10:34:20.523: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.141(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:48 10.86.2.129 2606: *Jul 26 10:34:21.959: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.205(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:49 10.86.2.129 2607: *Jul 26 10:34:22.959: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.20.22(0) -> 192.168.20.255(0), 1 packet
Dec 14 12:24:52 10.86.2.129 2608: *Jul 26 10:34:26.247: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.130(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:54 10.86.2.129 2609: *Jul 26 10:34:28.295: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.46(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:24:56 10.86.2.129 2610: *Jul 26 10:34:29.747: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.55.13(0) -> 80.251.55.127(0), 1 packet
Dec 14 12:24:57 10.86.2.129 2611: *Jul 26 10:34:31.419: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.57.222(0) -> 192.1.2.255(0), 1 packet
Dec 14 12:24:59 10.86.2.129 2612: *Jul 26 10:34:32.695: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.34(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:00 10.86.2.129 2613: *Jul 26 10:34:34.111: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.217(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:00 10.86.2.129 2614: *Jul 26 10:34:34.907: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 250 packets
Dec 14 12:25:00 10.86.2.129 2615: *Jul 26 10:34:34.907: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.210(0) -> 255.255.255.255(0), 150 packets
Dec 14 12:25:05 10.86.2.129 2616: *Jul 26 10:34:39.151: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.48.102(0) -> 255.255.255.255(0), 1 packet
Dec 14 12:25:08 10.86.2.129 2617: *Jul 26 10:34:41.915: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.47(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:12 10.86.2.129 2618: *Jul 26 10:34:46.207: %CDP-4-DUPLEX_MISMATCH: duplex mismatch discovered on FastEthernet4.1 (not half duplex), with SunBrew-Niznevartovsk Ethernet0/0 (half duplex).
Dec 14 12:25:14 10.86.2.129 2619: *Jul 26 10:34:47.639: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.130(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:16 10.86.2.129 2620: *Jul 26 10:34:50.515: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.134(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:18 10.86.2.129 2621: *Jul 26 10:34:51.799: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.141(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:20 10.86.2.129 2622: *Jul 26 10:34:53.639: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.135(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:21 10.86.2.129 2623: *Jul 26 10:34:55.079: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.50.4(0) -> 80.251.55.58(0), 1 packet
Dec 14 12:25:23 10.86.2.129 2624: *Jul 26 10:34:57.295: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.43(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:24 10.86.2.129 2625: *Jul 26 10:34:58.379: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.14(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:25 10.86.2.129 2626: *Jul 26 10:34:59.387: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.47(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:30 10.86.2.129 2627: *Jul 26 10:35:03.779: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.57.222(0) -> 192.1.2.255(0), 1 packet
Dec 14 12:25:31 10.86.2.129 2628: *Jul 26 10:35:04.967: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.20.2(0) -> 192.168.20.255(0), 1 packet
Dec 14 12:25:34 10.86.2.129 2629: *Jul 26 10:35:08.187: %SEC-6-IPACCESSLOGP: list Flood denied tcp 10.9.253.43(0) -> 80.251.55.58(0), 1 packet
Dec 14 12:25:39 10.86.2.129 2630: *Jul 26 10:35:12.735: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.20.29(0) -> 192.168.20.255(0), 1 packet
Dec 14 12:25:41 10.86.2.129 2631: *Jul 26 10:35:14.907: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.16(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:45 10.86.2.129 2632: *Jul 26 10:35:19.095: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.12(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:47 10.86.2.129 2633: *Jul 26 10:35:21.039: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.254(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:51 10.86.2.129 2634: *Jul 26 10:35:25.371: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.20.3(0) -> 192.168.20.255(0), 1 packet
Dec 14 12:25:54 10.86.2.129 2635: *Jul 26 10:35:28.459: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.14(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:25:59 10.86.2.129 2636: *Jul 26 10:35:33.175: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.20.2(0) -> 192.168.20.255(0), 1 packet
Dec 14 12:26:01 10.86.2.129 2637: *Jul 26 10:35:34.907: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 311 packets
Dec 14 12:26:01 10.86.2.129 2638: *Jul 26 10:35:34.907: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.57.146(0) -> 80.251.57.151(0), 34673 packets
Dec 14 12:26:05 10.86.2.129 2639: *Jul 26 10:35:39.343: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.26(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:26:06 10.86.2.129 2640: *Jul 26 10:35:40.367: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.48(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:26:09 10.86.2.129 2641: *Jul 26 10:35:42.819: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.20.29(0) -> 192.168.20.255(0), 1 packet
Dec 14 12:26:10 10.86.2.129 2642: *Jul 26 10:35:44.187: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.47(0) -> 192.168.0.255(0), 1 packet
Dec 14 12:26:11 10.86.2.129 2643: *Jul 26 10:35:45.443: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.57.222(0) -> 255.255.255.255(0), 1 packet
Dec 14 12:26:12 10.86.2.129 2644: *Jul 26 10:35:46.259: %CDP-4-DUPLEX_MISMATCH: duplex mismatch discovered on FastEthernet4.1 (not half duplex), with SunBrew-Niznevartovsk Ethernet0/0 (half duplex).
Dec 14 12:26:16 10.86.2.129 2645: *Jul 26 10:35:50.179: %SEC-6-IPACCESSLOGP: list Flood denied udp 80.251.56.196(0) -> 80.251.56.199(0), 1 packet
Dec 14 12:26:17 10.86.2.129 2646: *Jul 26 10:35:51.255: %SEC-6-IPACCESSLOGP: list Flood denied udp 192.168.0.254(0) -> 192.168.0.255(0), 1 packet

Блин.. какого рожна там "серые" адреса по udp летают?

slim
14.12.2007, 13:34
syslog c кошки

Блин.. какого рожна там "серые" адреса по udp летают?
етто называецо UDP Broadcast Flooding, у быдло-провайдеров такое бывает..

Sir Arthur
14.12.2007, 14:12
ето я понимать, админ провайдера говорит типа у него все ровно - разбирайтесь сами. Написал им письмо. Пусть смотрят что у них там накручено ибо я вижу с внешнего фейса сохи 4 девайса по сдп.. как - я хз.
статистика с сохи
RGSN-Niznevartovsk2#sh int f4
FastEthernet4 is up, line protocol is up
Hardware is PQUICC_FEC, address is 001a.e3b0.ef6d (bia 001a.e3b0.ef6d)
Description: WAN$FW_OUTSIDE$$ES_WAN$
MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation 802.1Q Virtual LAN, Vlan ID 1., loopback not set
Keepalive set (10 sec)
Full-duplex, 100Mb/s, 100BaseTX/FX
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:00:00, output 00:00:00, output hang never
Last clearing of "show interface" counters 03:33:49
Input queue: 1/75/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 104000 bits/sec, 129 packets/sec
5 minute output rate 2000 bits/sec, 3 packets/sec
895075 packets input, 92023244 bytes
Received 822778 broadcasts, 0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 watchdog
0 input packets with dribble condition detected
29813 packets output, 3608290 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 babbles, 0 late collision, 0 deferred
0 lost carrier, 0 no carrier
0 output buffer failures, 0 output buffers swapped out