Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 

Help !!!!!!!! IP flow Stats

Hi

Can anyone pls help me out in finding whts this stats shows ?is this an spoofin type of case or anythng related to that since the brdcast ip is 255.255.255.255 ??

SrcIf SrcIPaddress DstIf DstIPaddress Pr SrcP DstP Pkts

Se5/2 X.X.X.X Null 255.255.255.255 11 CC3C 0045 3

Se4/0 X.X.X.Y Null 255.255.255.255 11 CC3C 0045 3

Se5/2 X.X.X.X Null 255.255.255.255 11 C775 0045 6

Se4/0 X.X.X.Y Null 255.255.255.255 11 C775 0045 6

regds

prem

1 ACCEPTED SOLUTION

Accepted Solutions

Re: Help !!!!!!!! IP flow Stats

This is possibly output of "show ip cache flow".

Note that port numbers are in hex.

CC3C - 52284.

C775 - 51061.

The above are the source ports. ( we dont bother abt that).

0045 - 69 - which is TFTP port.

Probably if you see a lot of packets such as above, your network has been hit with the new W32 Blaster worm virus. The IP address of the machines which are affected are X.X.X.X and X.X.X.Y.

You will need to go to Microsoft.com and download the necessary patch as well as to remove the virus, go to www.symantec.com and download the FixBlast virus tool.

Note that there is a variant of the Blaster worm called, W32.Welchia worm, The TFTP traffic could be due to that too.

Hope that helps!

3 REPLIES

Re: Help !!!!!!!! IP flow Stats

This is possibly output of "show ip cache flow".

Note that port numbers are in hex.

CC3C - 52284.

C775 - 51061.

The above are the source ports. ( we dont bother abt that).

0045 - 69 - which is TFTP port.

Probably if you see a lot of packets such as above, your network has been hit with the new W32 Blaster worm virus. The IP address of the machines which are affected are X.X.X.X and X.X.X.Y.

You will need to go to Microsoft.com and download the necessary patch as well as to remove the virus, go to www.symantec.com and download the FixBlast virus tool.

Note that there is a variant of the Blaster worm called, W32.Welchia worm, The TFTP traffic could be due to that too.

Hope that helps!

Re: Help !!!!!!!! IP flow Stats

hi shankar

will be thkful if u can provdie me the link where i can convert the hexadec port numbers into decimal numbers..

thks

prem

Re: Help !!!!!!!! IP flow Stats

Prem,

No need of any link for that.

Open windows calculator (Start Menu - > Run-> calc -- hit enter key).

On the Calc software, go to View - > Scientific. Click scientific to see DEC, HEX, BIN options on the calc.

Now Check the HEX checkbox and input the hex string that you see on the output of "show ip cache flow".

After you input the string, check the DEC checkbox. This will immediately convert your HEX port number into DEC (decimal) port number.

Or you could do a manual calculation.

Any hex number say ABCD =

A*16exp3+B*16exp2+C*16exp1+D*16exp0.

Calculating using the above formula,

0045 for example =

0*16exp3+0*16exp2+4*16exp1+5*16exp0 = 16*4+5=69

which is TFTP

Hope that helps!@

99
Views
0
Helpful
3
Replies
CreatePlease to create content