- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- Re: HP Procurve 5308xl hangs in case of teardrop a...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-26-2003 10:51 PM
тАО08-26-2003 10:51 PM
HP Procurve 5308xl hangs in case of teardrop attack
I've several hp 5308xl, all of them configured with ospf routing, no ip directed broadcast (for smurfing attacks) and broadcast limit activated.
This helped me a lot to avoid DoS attacks on my net. Unfortunately, I can't avoid teardrop attack, caused by some viruses.
An infected computer flooded the net with ip fragments: the 5308xl switch hangs, showing a cpu load of 7000 percent.
Any suggestion to avoid this ?
TIA,
Massimo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-27-2003 01:23 AM
тАО08-27-2003 01:23 AM
Re: HP Procurve 5308xl hangs in case of teardrop attack
I'm trying to find a way to manage DOS countermeasures in HP switches. Its a shame they dont have the same functions for DOs attacks as Extreme or Cisco has.
Regards,
Johan Eriksson
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-27-2003 03:19 AM
тАО08-27-2003 03:19 AM
Re: HP Procurve 5308xl hangs in case of teardrop attack
It could be IGMP, but I think that the broadcast-limit statement in the 5308xl configuration shoould block them.
The strange thing is that a single machine (this is my case) can hang a switch with a large backplane as the 53xx.
That makes me think that are some bug in the TCP/IP stack of the 53xx, and if the routing is enabled, sending an ip fragments flood with bad offset values can hang the switch. I think that the switch tries to reassembly the packets, with high cpu load values.
Using a keyword 'fragments' in the access-list statement (as in IOS) could help: unfortunately, this keyword does not exist in the Procurve 53xx.
Massimo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-27-2003 10:56 AM
тАО08-27-2003 10:56 AM
Re: HP Procurve 5308xl hangs in case of teardrop attack
Procurve 2524 has some configurable threshold for broadcast limiting, 5300XL does not seem to have any options for that.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-27-2003 10:41 PM
тАО08-27-2003 10:41 PM
Re: HP Procurve 5308xl hangs in case of teardrop attack
With Procurve 53xx you don't need to specify it, because the switch adapt the allowed bandwidth automatically.
Massimo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-28-2003 04:50 AM
тАО08-28-2003 04:50 AM
Re: HP Procurve 5308xl hangs in case of teardrop attack
Back to the first message: What you are saying is that if ONE computer with 100mbps uplink sends bad packets to the 530x switch it hangs? Is this correct? Have you reported this to the HP support?
Johan Eriksson
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-28-2003 05:27 AM
тАО08-28-2003 05:27 AM
Re: HP Procurve 5308xl hangs in case of teardrop attack
"Broadcast limit - Reduces the bandwidth for broadcast and _multicast_ traffic on all ports on the switch. Any broadcast or multicast overload will be dropped. This feature is not appropriate for networks that require high levels of IPX or RIP broadcast traffic".
So, if you use the broadcast-limit statement, the switch should limit broadcast/multicast bandwidth.
Back to my problem: YES, if there is an ip fragments flood (with overlap offset) the switch hangs.
I reported the problem to HP today.
Maybe that Procurve 5300xl series is not rfc 1858 compliant?
Massimo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-28-2003 05:42 AM
тАО08-28-2003 05:42 AM
Re: HP Procurve 5308xl hangs in case of teardrop attack
"Configuring a Broadcast Limiting on the Switch. Executing this command
configures broadcast limiting for all ports on the switch.
Syntax: broadcast-limit"
(and that the current setting can be seen from "show run" output)
Great that you bring up any issues with 5300XL. There are so few user comments in the net about that device.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-28-2003 05:55 AM
тАО08-28-2003 05:55 AM
Re: HP Procurve 5308xl hangs in case of teardrop attack
The quoted paragraph is in chapter 9, 9-4; see also 9-11.
Massimo
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО08-28-2003 10:53 AM
тАО08-28-2003 10:53 AM