wg-multicast - Re: Please filter TCP to 224/4 [was MSDP SA explosion - sasser worm?]
Subject: All things related to multicast
List archive
- From: Amel Caldwell <>
- To: "Charles R. Anderson" <>
- Cc:
- Subject: Re: Please filter TCP to 224/4 [was MSDP SA explosion - sasser worm?]
- Date: Tue, 4 May 2004 10:31:12 -0700 (Pacific Standard Time)
I have been doing this with ACLs at our borders for a year or so already, this
does not prevent the MSDP SA explosion though.
I think to do this effectively, you would need to do it at the edge via
multicast boundaries and probably through SA filtering as well. In addition
to filtering TCP to 224/4 is it reasonable to filter privileged port ( < 1024)
traffic to 224/4? Do multicast boundaries and SA filters have this
capability?
Amel
On Mon, 3 May 2004, Charles R. Anderson wrote:
>Folks, please filter TCP packets destined to 224/4. TCP can't do
>multicast, and that should help reduce the MSDP load caused by Sasser.
>
>Thanks.
>
>On Mon, May 03, 2004 at 12:48:28PM -0700, Amel Caldwell wrote:
>> Actually, I have been looking at the very same thing here at the
>> University of
>> Washington. I picked out six local addresses that were responsible for
>> 800+
>> SA entries and they all appeared to be infected with SASSER.
>>
>> Amel
>>
>> On Mon, 3 May 2004, Bill Owens wrote:
>>
>> >A pointer on another list got me looking at my MSDP SA cache, with the
>> >suggestion that the sasser worm might be scanning multicast space. I'm not
>> >sure that's the case, since it doesn't look the same as back when ramen
>> >was
>> >hitting us, but there's definitely something going on. My SA cache is
>> >currently at 33k and rising.
>> >
>> >Bill.
>> >
>> >
>>
>
>
- MSDP SA explosion - sasser worm?, Bill Owens, 05/03/2004
- Re: MSDP SA explosion - sasser worm?, Greg Shepherd, 05/03/2004
- Re: MSDP SA explosion - sasser worm?, Bill Owens, 05/03/2004
- Re: MSDP SA explosion - sasser worm?, David Farmer, 05/03/2004
- Re: MSDP SA explosion - sasser worm?, Bruce Curtis, 05/03/2004
- Re: MSDP SA explosion - sasser worm?, David Farmer, 05/03/2004
- Re: MSDP SA explosion - sasser worm?, Doug Pearson, 05/03/2004
- Re: MSDP SA explosion - sasser worm?, Bill Owens, 05/03/2004
- Re: MSDP SA explosion - sasser worm?, Amel Caldwell, 05/03/2004
- Please filter TCP to 224/4 [was MSDP SA explosion - sasser worm?], Charles R. Anderson, 05/03/2004
- Re: Please filter TCP to 224/4 [was MSDP SA explosion - sasser worm?], Amel Caldwell, 05/04/2004
- Please filter TCP to 224/4 [was MSDP SA explosion - sasser worm?], Charles R. Anderson, 05/03/2004
- Re: MSDP SA explosion - sasser worm?, Bill Owens, 05/04/2004
- Re: MSDP SA explosion - sasser worm?, William F. Maton, 05/04/2004
- Re: MSDP SA explosion - sasser worm?, Marshall Eubanks, 05/04/2004
- Re: MSDP SA explosion - sasser worm?, David Farmer, 05/04/2004
- Re: MSDP SA explosion - sasser worm?, Marshall Eubanks, 05/04/2004
- Re: MSDP SA explosion - sasser worm?, Charles R. Anderson, 05/04/2004
- Re: MSDP SA explosion - sasser worm?, Bill Owens, 05/04/2004
- Re: MSDP SA explosion - sasser worm?, shep, 05/04/2004
- Re: MSDP SA explosion - sasser worm?, Charles R. Anderson, 05/04/2004
- Re: MSDP SA explosion - sasser worm?, Leonard Giuliano, 05/04/2004
- Reliable Multicast, Patcharee Basu, 05/07/2004
- Re: MSDP SA explosion - sasser worm?, Leonard Giuliano, 05/04/2004
- Re: MSDP SA explosion - sasser worm?, Bill Owens, 05/04/2004
- Re: MSDP SA explosion - sasser worm?, William F. Maton, 05/04/2004
- Re: MSDP SA explosion - sasser worm?, Greg Shepherd, 05/03/2004
Archive powered by MHonArc 2.6.16.