Asking for an advice.
On our K12-district we have multiple UniFi-UAP's and Aruba 2540-24G-PoE+-4SFP switches. All switches is configured to use fault-finder for broadcast-storm ( warn-and-disable 300pps). We have experienced multiple broadcast-alarms in those ports where UniFi-UAP is connected, everyday in a past couple weeks.
W 10/15/21 10:50:40 02675 FFI: port 43-Excessive Broadcasts. Broadcast-storm
control threshold 300 pps exceeded.
M 10/15/21 10:50:40 02673 FFI: port 43-Port disabled by Fault-finder.
I 10/15/21 10:50:40 00898 ports: Fault Finder(71) has disabled port 43 for 600
seconds
I 10/15/21 10:50:40 00077 ports: port 43 is now off-line
I 10/15/21 11:00:40 00900 ports: port 43 timer (71) has expired
I 10/15/21 11:00:42 00076 ports: port 43 is now on-line
This have happened before(last year) and i did manage to capture network traffic with wireshark from those ports when that broadcast was happening. In these cases there was tons of ARP packets coming from one device and i blocked that device accessing our wireless from Unifi control panel. But now this broadcast is different.
This time we are getting loads of SNMP packets from one device(Oneplus Nord smartphone), over 40k packets in 1 minute. And this why we are getting broadcast alarms..
Source is that smartphone, and destination is 255.255.255.255
14556676 2021-10-15 09:00:59,999581 10.14.215.177 255.255.255.255 SNMP 140 get-request 1.3.6.1.2.1.1.2.0 1.3.6.1.4.1.2435.2.3.9.4.2.1.5.5.1.0 1.3.6.1.4.1.11.2.3.9.1.1.3.0 1.3.6.1.2.1.2.2.1.6.1
I have no idea what is going on on that phone?
No comments:
Post a Comment