cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
350
Views
0
Helpful
3
Replies

Help !!!!!!!! IP flow Stats

spremkumar
Level 9
Level 9

Hi

Can anyone pls help me out in finding whts this stats shows ?is this an spoofin type of case or anythng related to that since the brdcast ip is 255.255.255.255 ??

SrcIf SrcIPaddress DstIf DstIPaddress Pr SrcP DstP Pkts

Se5/2 X.X.X.X Null 255.255.255.255 11 CC3C 0045 3

Se4/0 X.X.X.Y Null 255.255.255.255 11 CC3C 0045 3

Se5/2 X.X.X.X Null 255.255.255.255 11 C775 0045 6

Se4/0 X.X.X.Y Null 255.255.255.255 11 C775 0045 6

regds

prem

1 Accepted Solution

Accepted Solutions

thisisshanky
Level 11
Level 11

This is possibly output of "show ip cache flow".

Note that port numbers are in hex.

CC3C - 52284.

C775 - 51061.

The above are the source ports. ( we dont bother abt that).

0045 - 69 - which is TFTP port.

Probably if you see a lot of packets such as above, your network has been hit with the new W32 Blaster worm virus. The IP address of the machines which are affected are X.X.X.X and X.X.X.Y.

You will need to go to Microsoft.com and download the necessary patch as well as to remove the virus, go to www.symantec.com and download the FixBlast virus tool.

Note that there is a variant of the Blaster worm called, W32.Welchia worm, The TFTP traffic could be due to that too.

Hope that helps!

Sankar Nair
UC Solutions Architect
Pacific Northwest | CDW
CCIE Collaboration #17135 Emeritus

View solution in original post

3 Replies 3

thisisshanky
Level 11
Level 11

This is possibly output of "show ip cache flow".

Note that port numbers are in hex.

CC3C - 52284.

C775 - 51061.

The above are the source ports. ( we dont bother abt that).

0045 - 69 - which is TFTP port.

Probably if you see a lot of packets such as above, your network has been hit with the new W32 Blaster worm virus. The IP address of the machines which are affected are X.X.X.X and X.X.X.Y.

You will need to go to Microsoft.com and download the necessary patch as well as to remove the virus, go to www.symantec.com and download the FixBlast virus tool.

Note that there is a variant of the Blaster worm called, W32.Welchia worm, The TFTP traffic could be due to that too.

Hope that helps!

Sankar Nair
UC Solutions Architect
Pacific Northwest | CDW
CCIE Collaboration #17135 Emeritus

hi shankar

will be thkful if u can provdie me the link where i can convert the hexadec port numbers into decimal numbers..

thks

prem

Prem,

No need of any link for that.

Open windows calculator (Start Menu - > Run-> calc -- hit enter key).

On the Calc software, go to View - > Scientific. Click scientific to see DEC, HEX, BIN options on the calc.

Now Check the HEX checkbox and input the hex string that you see on the output of "show ip cache flow".

After you input the string, check the DEC checkbox. This will immediately convert your HEX port number into DEC (decimal) port number.

Or you could do a manual calculation.

Any hex number say ABCD =

A*16exp3+B*16exp2+C*16exp1+D*16exp0.

Calculating using the above formula,

0045 for example =

0*16exp3+0*16exp2+4*16exp1+5*16exp0 = 16*4+5=69

which is TFTP

Hope that helps!@

Sankar Nair
UC Solutions Architect
Pacific Northwest | CDW
CCIE Collaboration #17135 Emeritus
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: