Solved

IGMP 239.255.255.254 packets flooding my network

Posted on 2003-10-30
7
2,722 Views
Last Modified: 2013-12-07
We currently use all Asante IntraCore Switchs. My network has become very slow. We have all IMACS using apple talk on the network.

Checking with a packet analyer I saw millions of packets on my network going to the ip address 239.255.255.254 with a type IGMP.

Thinking I had a couple of bad machines today I unplugged the machines that were sending the packets. When I unplugged a machine that causing the packets it would take 10 minutes and the network would go back to normal.

Then another machine would start to flood the network. It only happened when the machines booted up. If a machine didn't cause the problem on boot it would work fine.

I look some stuff up and it says that I should enable Enable IGMP snooping and  Enable L3 Query device.

First what is l3 query device and will this stop my switches from get flooded.

Also Asante has me disable spanning tree because it doesn't work with well with Apple Talk.

HELP PLEASE

.
0
Comment
Question by:MSGROVE
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 7

Expert Comment

by:NicBrey
ID: 9656184
IGMP packets are IP multicast packets. Multicast is handled by routers on a network. IGMP snooping is just what helps the switches get multicast address and group information from the routers. It will not help you in this case. Enabling layer 3 on your switches will also not really help unless you redisgn your nework with VLANs.
 
Looks like you have applications on your MACs that look for multicast hosts to join in a group with at startup. I recon that your easiest bet is to try and find the application that want to join multicast groups and to disable it if you don't use them. You say the MACs communicate with appletalk, is TCP/IP installed or configured on them??  
0
 
LVL 35

Expert Comment

by:ShineOn
ID: 9656265
Why are you using appletalk on your network?  I thought iMac systems could handle "pure" IP?  

Appletalk is very chatty.  

I would recommend reconfiguring it all to use IP exclusively, with no appletalk at all.
0
 
LVL 7

Expert Comment

by:NicBrey
ID: 9656282
Agree with ShineOn. Change to IP if you can and remove appletalk. You will still have to find the applications that send the IGMP requests though.  Applications that use multicast is usually multimedia type applications like video conference applications and video/audio streaming applications.
0
Don't Cry: How Liquid Web is Ensuring Security

WannaCry is just the start. Read how Liquid Web is protecting itself and its customers against new threats.

 
LVL 3

Expert Comment

by:_tack
ID: 9656294
Old switches and non L3 switch will forward multicast traffic as broadcast to all segments,
new L3 switches do know Multicast traffic and will forward it only where requested, (IGMP join request needed)
introducing L3 policies will just limit the traffic to some segments, but will not solve your problem

0
 

Author Comment

by:MSGROVE
ID: 9660622
Thanks for your help everyone but I beleive I solved my problem.


Our switches were running on L2 and were treating multicast as broadcast. We inable igmp sniffing on the routers and it has slow down the packets. Also talking with Asante again today they had a firmware update that helped with this.

0
 
LVL 1

Accepted Solution

by:
GhostMod earned 0 total points
ID: 11532653
PAQed, with points refunded (500)

GhostMod
Community Support Moderator
0

Featured Post

Why Off-Site Backups Are The Only Way To Go

You are probably backing up your data—but how and where? Ransomware is on the rise and there are variants that specifically target backups. Read on to discover why off-site is the way to go.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question