Friday, October 15, 2021

SNMP storm?

Asking for an advice.

On our K12-district we have multiple UniFi-UAP's and Aruba 2540-24G-PoE+-4SFP switches. All switches is configured to use fault-finder for broadcast-storm ( warn-and-disable 300pps). We have experienced multiple broadcast-alarms in those ports where UniFi-UAP is connected, everyday in a past couple weeks.

W 10/15/21 10:50:40 02675 FFI: port 43-Excessive Broadcasts. Broadcast-storm

control threshold 300 pps exceeded.

M 10/15/21 10:50:40 02673 FFI: port 43-Port disabled by Fault-finder.

I 10/15/21 10:50:40 00898 ports: Fault Finder(71) has disabled port 43 for 600

seconds

I 10/15/21 10:50:40 00077 ports: port 43 is now off-line

I 10/15/21 11:00:40 00900 ports: port 43 timer (71) has expired

I 10/15/21 11:00:42 00076 ports: port 43 is now on-line

This have happened before(last year) and i did manage to capture network traffic with wireshark from those ports when that broadcast was happening. In these cases there was tons of ARP packets coming from one device and i blocked that device accessing our wireless from Unifi control panel. But now this broadcast is different.

This time we are getting loads of SNMP packets from one device(Oneplus Nord smartphone), over 40k packets in 1 minute. And this why we are getting broadcast alarms..

Source is that smartphone, and destination is 255.255.255.255

14556676 2021-10-15 09:00:59,999581 10.14.215.177 255.255.255.255 SNMP 140 get-request 1.3.6.1.2.1.1.2.0 1.3.6.1.4.1.2435.2.3.9.4.2.1.5.5.1.0 1.3.6.1.4.1.11.2.3.9.1.1.3.0 1.3.6.1.2.1.2.2.1.6.1

I have no idea what is going on on that phone?



No comments:

Post a Comment