ALM-3276800097 Invalid ARP packet
Description
SECE/4/ARP_PACKET_CHECK: OID [OID] Invalid packet. (SourceInterface=[OCTET], SourceIP=[OCTET], SourceMAC=[OCTET], OuterVlan=[INTEGER], InnerVlan=[INTEGER])
The system detects invalid ARP packets.
Attribute
Alarm ID |
Alarm Severity |
Alarm Type |
---|---|---|
3276800097 |
Warning |
Equipment alarm |
Parameters
Name |
Meaning |
---|---|
OID |
Indicates the MIB object ID of the alarm. |
SourceInterface |
Indicates the source interface of packets. |
SourceIP |
Indicates the source IP address of packets. |
SourceMAC |
Indicates the source MAC address of packets. |
OuterVlan |
Indicates the outer VLAN ID of packets. |
InnerVlan |
Indicates the inner VLAN ID of packets. |
Impact on the System
If this alarm is generated, the device may be attacked. If the attack traffic volume is heavy, the device is busy processing attack packets. As a result, services of authorized users are interrupted.
Possible Causes
The device receives invalid ARP packets.
Procedure
- Find the interface where the gateway conflict occurs according to the value of SourceInterface.
- Lock the user who sends gateway conflict packets according to the values of SourceMAC and PVLAN.
- Check whether the allocated address of the user conflicts with the gateway address. If the address conflicts, allocate an address to the user again. If the address does not conflict, the user may be the attacker. In this case, you can take such measures as disconnecting the user.
Related Information
None
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot