Want to protect your cyber security and still get fast solutions? Ask a secure question today.Go Premium

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1118
  • Last Modified:

IGMP V2 Membership Query

Without getting into details at first, just want a broad explanation.
Can someone explain what would cause the following:
Packet capture example:
Source add.     Dest add                
10.10.1.1          239.255.67.250    IGMP   IGMP V2 Membership Query .....

once it starts it wont stop until the core switch (10.10.1.1) is shut off and back on
1.5 Million times in 3 minutes. It chokes the rest of the network and things stop.

Why would it continue non-stop?


0
MrRude
Asked:
MrRude
  • 2
  • 2
1 Solution
 
Don JohnstonInstructorCommented:
Half a million packets per minute is a bit much. Do you have a loop in your network somewhere?
0
 
MrRudeAuthor Commented:
Not that I am aware of. This is a large manufacturing facility and this just pops up at random. We can go along well for weeks and then out of the clear blue - BAM!
Seems to be happening only on days. Nights and weekends never have the issue and production is in full operation. No engineers or office personel nights or weekends. I figured something is being plugged in or triggered somehow, but would like to understand the "Query" better.I assume something triggers the core (which is PIM RP) to query that multicast group. I just can't grasp why it would continue nonstop.
0
 
Don JohnstonInstructorCommented:
In multicast, when a host wants to receive a stream, it will send out an IGMP join message. The router providing that stream to the network will then begin forwarding the stream onto the network. There can be many hosts receiving the same stream. When one of the hosts receiving a multicast stream leaves the group. That host sends an IGMP leave message.

The router that is providing the stream onto that network segment sends out an IGMP group query (to the multicast address). If there are any remaining devices which are still interested in receiving the stream, they will respond. If nobody responds to the query, the router will stop the multicast stream.

The router only sends one query. So what I think might be happening is that you've got a loop and that query is replicating in the loop. Basically a broadcast storm since broadcast and multicast are handled the same way.

0
 
MrRudeAuthor Commented:
This is the direction I was needing to be pointed in.
Thanks a bunch!
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now