- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- 5308 & icmp type 5 flood
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-26-2009 03:23 AM
тАО10-26-2009 03:23 AM
Hope someone has a suggestion on how to resolve a small problem I'm seeing.
Have a network infrastructure consisting of 2 x 5308XL using xrrp failover connecting 4 HP C7000 blade chassis using nortel GBe2c switches, all seems to be functioning ok but we are seeing massive volumes of icmp type 5 traffic which appears to be coming from the primaray 5308's management IP.
The traffic eventually gets routed to the boundary firewall which drops & logs it, the destination address is in 169.254.x.x but I really do not understand why the switch would be sending such traffic.
Any ideas or suggestions would be appreciated.
Cheers
Matt
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-26-2009 03:32 PM
тАО10-26-2009 03:32 PM
SolutionICMP type 5 are redirects which means:
The ICMP redirect message indicates that the gateway to which the host sent the datagram is no longer the best gateway to reach the net in question. The gateway will have forwarded the datagram, but the host should revise its routing table to have a different immediate address for this net.
The address looks like a Windows PC that can't get an address via DHCP and it falls back to using a 169.x.x.x address.
Find the MAC address of the device sending this and stop it there.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-26-2009 03:47 PM
тАО10-26-2009 03:47 PM
Re: 5308 & icmp type 5 flood
thanks for the info, do you know if the mac address will be in the data portion of the packets?
Cheers
Matt
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-26-2009 03:58 PM
тАО10-26-2009 03:58 PM
Re: 5308 & icmp type 5 flood
yes, it should be (source mac) but you can also do a "show arp" on the 53xx and look for the 169.x.x.x address.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО10-27-2009 07:12 PM
тАО10-27-2009 07:12 PM
Re: 5308 & icmp type 5 flood
sh arp didn't turn up anything recognisable as the 169.254.x.x address in question however, it appears there are two "issues" one is that the icmp type 5 packets are correct, the boundary firewall is not using the most efficient path, thus the switch is letting it know. Secondly, since a firmware update the firewall is now seeing these packets on its HA interface and rejecting them causing the logging problem.
Thanks again for pointing me in the right direction.
Cheers
Matt