Page 1 of 1

[ask]How to block UDP Flood on OS7700 ?

Posted: 24 Oct 2010 08:13
by wongjowo
Hi, Just want to ask it is normal UDP traffic like this?

http://img716.imageshack.us/i/vlan203guest22102010.jpg

my network became very slow after this happen in my network, the strange is why so many traffic with IP 172.16.5.1 but using many different MAC ADDRESS?

since I'm new with Wireshark i dunno it is serious problem or not but my network getting very slow.

if broadcast address is 255.255.255.255 would it be broadcast in network 172.16.5.0 or it can be broadcast in all different network in one vlan? my network in 172.16.2.0 its very slow, it is possible because of this?

i already use policy service to drop UDP Port but it seems not working.

Please help

Posted: 29 Oct 2010 06:02
by cedric1
hello

If your network is slow, this is because you are under and udp flood attack.

You can limit flood rate on a port, check cli doc for the command.

interfaces 3/1 flood rate 400
400 = 400Mbs
best try with 1


Best is to shut port where this station is connected and check what is wrong on this station.