问题描述:
日志如下
%Jun 24 11:12:19:743 2024 NHX-JF-S10508X-G STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Jun 24 11:12:22:422 2024 NHX-JF-S10508X-G DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=2-Slot=2; Auto port-defend started.SourceAttackInterface=Ten-GigabitEthernet2/2/0/51, AttackProtocol= ARP
%Jun 24 11:12:22:453 2024 NHX-JF-S10508X-G DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=1-Slot=2; Auto port-defend started.SourceAttackInterface=Ten-GigabitEthernet1/2/0/51, AttackProtocol= ARP
%Jun 24 11:12:45:856 2024 NHX-JF-S10508X-G DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=1-Slot=2; Auto port-defend stopped.SourceAttackInterface=Ten-GigabitEthernet1/2/0/51, AttackProtocol= ARP
%Jun 24 11:12:46:903 2024 NHX-JF-S10508X-G DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=2-Slot=2; Auto port-defend stopped.SourceAttackInterface=Ten-GigabitEthernet2/2/0/51, AttackProtocol= ARP
想咨询的是怎么进行溯源查看具体是那个IP地址在发送大量的ARP广播报文,还有就是ARP攻击默认的阈值是多少超过这个阈值是不是就会报这个问题
组网及组网描述:
日志如下
%Jun 24 11:12:19:743 2024 NHX-JF-S10508X-G STP/6/STP_NOTIFIED_TC: Instance 0's port Bridge-Aggregation1 was notified a topology change.
%Jun 24 11:12:22:422 2024 NHX-JF-S10508X-G DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=2-Slot=2; Auto port-defend started.SourceAttackInterface=Ten-GigabitEthernet2/2/0/51, AttackProtocol= ARP
%Jun 24 11:12:22:453 2024 NHX-JF-S10508X-G DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=1-Slot=2; Auto port-defend started.SourceAttackInterface=Ten-GigabitEthernet1/2/0/51, AttackProtocol= ARP
%Jun 24 11:12:45:856 2024 NHX-JF-S10508X-G DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=1-Slot=2; Auto port-defend stopped.SourceAttackInterface=Ten-GigabitEthernet1/2/0/51, AttackProtocol= ARP
%Jun 24 11:12:46:903 2024 NHX-JF-S10508X-G DRVPLAT/4/PORT_ATTACK_OCCUR: -Chassis=2-Slot=2; Auto port-defend stopped.SourceAttackInterface=Ten-GigabitEthernet2/2/0/51, AttackProtocol= ARP
想咨询的是怎么进行溯源查看具体是那个IP地址在发送大量的ARP广播报文,还有就是ARP攻击默认的阈值是多少超过这个阈值是不是就会报这个问题
暂无评论