- 积分
- 625
- 鸿鹄币
- 个
- 好评度
- 点
- 精华
- 注册时间
- 2009-9-5
- 最后登录
- 1970-1-1
- 阅读权限
- 40
- 听众
- 收听
中级工程师
|
楼主 |
发表于 2017-5-10 22:20:52
|
显示全部楼层
恩,谢谢你的建议,现在已初步判断为ARP攻击了,通过科来分析仪发现其中一台终端异常。等待进一步确认,不过问题已经很明了了。
CPCAR on slot 6
-------------------------------------------------------------------------------
Packet Type Pass(Bytes) Drop(Bytes) Pass(Packets) Drop(Packets)
arp-request 61110852 3902005092 898689 57382426
arp-reply 440480014 168232 6477581 2473
异常接口如下:
GigabitEthernet6/0/31 current state : UP
Description:to_5F_S3352_1
Switch Port,PVID : 1,The Maximum Frame Length is 9216
IP Sending Frames' Format is PKTFMT_ETHNT_2, Hardware address is 0025-9ee5-891d
Port Mode: COMMON FIBER
Speed : 1000, Loopback: NONE
Duplex: FULL, Negotiation: DISABLE
Mdi : NORMAL
Last 300 seconds input rate 3140232 bits/sec, 5660 packets/sec
Last 300 seconds output rate 906240 bits/sec, 117 packets/sec
Input: 635464704 packets, 46453039903 bytes
Unicast: 27022210, Multicast: 496615
Broadcast: 607945879, Jumbo: 0
Total Error: 0, Discard: 0
|
8#
2017-5-10 22:20:52
回复(0)
收起回复
|