wg-multicast - Re: SAP storm from 145.19.1.183
Subject: All things related to multicast
List archive
- From: Zenon Mousmoulas <>
- To:
- Cc: "Julian Y. Koh" <>,
- Subject: Re: SAP storm from 145.19.1.183
- Date: Thu, 19 Jun 2008 15:03:36 +0300
On 19 Ιουν 2008, at 2:46 ΜΜ,
wrote:
Hi,
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
We're seeing a SAP storm this morning from 145.19.1.183 in the Netherlands
starting around 5:30am CDT (GMT-0500). Anyone else? We were able to block
it pretty quickly at our border, so I'm not sure if it's still going on.
we suffered this one too - which invoked my wrath enough to get around
to attempt further micro policing. I wonder if any IOS-heads could
have a look at this and see if it passes muster... (?)
----config snippet----
class-map match-all SAP-classmap
match access-group name SAP-mcast-group
!
!
policy-map SAP-policy
class SAP-classmap
police flow mask src-only 50000 1500 conform-action transmit exceed-action drop
interface gi9/1
(blah blah)
service-policy input SAP-policy
(blah blah)
ip access-list extended SAP-mcast-group
permit udp any host 224.2.127.254
permit udp host 224.2.127.254 any
You don't need the second entry in the acl (it could also be a simple standard acl). Apart from that, it looks ok. This will only work on 7600 and Cat 6500 though. This is according not to my personal experience but to suggestions from another thread, which I will forward right after this.
Z.
- Re: SAP storm from 145.19.1.183, (continued)
- Re: SAP storm from 145.19.1.183, A . L . M . Buxey, 06/19/2008
- Re: SAP storm from 145.19.1.183, Frank Fulchiero, 06/19/2008
- Re: SAP storm from 145.19.1.183, A . L . M . Buxey, 06/19/2008
- Re: SAP storm from 145.19.1.183, A . L . M . Buxey, 06/19/2008
- Re: SAP storm from 145.19.1.183, Tim Chown, 06/27/2008
- Re: SAP storm from 145.19.1.183, Marshall Eubanks, 06/27/2008
- Re: SAP storm from 145.19.1.183, Bill Owens, 06/27/2008
- Re: SAP storm from 145.19.1.183, Marshall Eubanks, 06/27/2008
- Message not available
- Re: SAP storm from 145.19.1.183, Tim Chown, 06/27/2008
- Re: SAP storm from 145.19.1.183, Zenon Mousmoulas, 06/19/2008
- RE: SAP storm from 145.19.1.183, Taylor, Scott J., 06/19/2008
- Re: SAP storm from 145.19.1.183, Zenon Mousmoulas, 06/20/2008
- Re: SAP storm from 145.19.1.183, Niels den Otter, 06/20/2008
- Re: SAP storm from 145.19.1.183, Frank Fulchiero, 06/20/2008
- Re: SAP storm from 145.19.1.183, Zenon Mousmoulas, 06/20/2008
- Re: SAP storm from 145.19.1.183, Frank Fulchiero, 06/20/2008
- Re: SAP storm from 145.19.1.183, A . L . M . Buxey, 06/20/2008
- Re: SAP storm from 145.19.1.183, Frank Fulchiero, 06/20/2008
- fixing miniSAP, Marc Manthey, 06/22/2008
- Re: SAP storm from 145.19.1.183, Zenon Mousmoulas, 06/20/2008
- Re: SAP storm from 145.19.1.183, Frank Fulchiero, 06/20/2008
- Re: SAP storm from 145.19.1.183, Niels den Otter, 06/20/2008
- Re: SAP storm from 145.19.1.183, Zenon Mousmoulas, 06/20/2008
Archive powered by MHonArc 2.6.16.