Solved

HSRP messages on Netscreen

Posted on 2006-06-13
4
549 Views
Last Modified: 2008-01-09
I keep getting message on our netscreen as a spoof alert stating that two of our swithces are generating packets in the order of source " ip address of one of our switches" src port 1985 and destination addres of 224.0.0.2 dsn port of 1985. My question is how to prevent this message as a spoof or turn the multicast broadcasting off on the switches.

thanks in advance
0
Comment
Question by:vcon13
  • 3
4 Comments
 
LVL 28

Expert Comment

by:mikebernhardt
ID: 16897305
You definitely don't want to block those packets- that's the hello protocol between the 2 switches. Block it and you won't have HSRP.

Not sure how to fix that issue on the netscreen, but it sounds like the problem is that the packets are on the outside of the netscreen but the netscreen is expecting them on the inside due to their source address. Without knowing your topology I can't really suggest further. You haven't said what brand of switches or anything. By default, multicast packets are treated as broadcasts on a switch. You can configure many Cisco switches so that only specific ports will be used for a particualr multicast group. So you may be able to supress them on the netscreen port that way. but the real problem is probably the design and how the netscreen fits into it with it's current configuration.
0
 
LVL 28

Expert Comment

by:mikebernhardt
ID: 16897328
you can also use IGMP snooping on the switches, which will help the switches figure out on which ports to send the multicast packets. It should stop sending them to the netscreen. But it won't stop arps and other possible broadcasts you may also be getting complaints about.
0
 

Author Comment

by:vcon13
ID: 16897797
Sorry, the switches are Cisco 4506 GBit, on the same subnet as the spoofed address. 10.10.10.0 we will use this subntet for this example. 6 interfaces on Netscreen. Inernas subnet is getting the message.
0
 
LVL 28

Accepted Solution

by:
mikebernhardt earned 500 total points
ID: 16898026
Hard to imagine why the Netscreen would have a problem with local addresses sending packets on the proper interface. The 4506s definitely do IGMP snooping, that may well fix the problem by keeping those multicast packets away from switchports that don't want to listen.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question