cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
287
Views
5
Helpful
3
Replies

has anyone seen this with the 4006 switch?

lchance
Level 1
Level 1

when i try to SNMP monitor this switch, even with two very different Network Management systems (CA Unicenter & Solarwinds) i get this same Syslog Message event flood:

2008 May 20 10:30:12 CDT -05:00 %IP-6-UDP_SOCKOVFL:UDP socket overflow from Source IP: 10.10.10.10, Destination port: 161

has anyone seen this event also?

and if so any ideas how to prevent it?

thanks,

larry

3 Replies 3

gpulos
Level 8
Level 8

This error indicates all buffers on the NMP for the UDP socket have filled up due to too much udp traffic from 10.10.10.10 on the vlan.

To prevent it, you must either block that udp traffic from 10.10.10.10 or remove it altogether.

If you don't you will continue to have udp packet loss.

Is 10.10.10.10 configured correctly? Is there too much snmp traffic?

Verify with a sniffer exactly what traffic is on the wire and its source/destination/port.

You can use the Error Message Decoder to assist in understanding error messages:

http://www.cisco.com/cgi-bin/Support/Errordecoder/index.cgi

(requires cco login)

A good free sniffer to use is ethereal/wireshark located at the following link:

http://ethereal.com/download.html

glen.grant
VIP Alumni
VIP Alumni

Yes this is a common message on catos . It means your monitoring equipment is polling the switch faster than it can handle the snmp polls. On newer code versions make sure your snmp buffer statement is set as high as it will go , think it is 95 . If still seen the only way to get rid of it is to throttle the snmp poll rate to the switches from the management tool. The messages do not hurt anything and is basically informational. If you don't want to see them in the logs then you could also set your logging for UDP to something below a "6" .

Amit Singh
Cisco Employee
Cisco Employee

Hi Larry,

Here is the information that I have got about the error :

Error Message IP-6-UDP_SOCKOVFL: UDP socket overflow from Source

IP:[chars], Destination port:[dec]

Explanation This message indicates that all buffers for a UDP socket on the Network Management Processor (NMP) have filled up due to excessive UDP traffic on the administrative VLAN. [chars] is the source IP address and [dec] is the destination port number.

Recommended Action Remove or block the source of the UDP packets to prevent further UDP packet loss.

Let me know if that helps.

regards,

-amit singh

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card