cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
484
Views
0
Helpful
2
Replies

ICMP Flood - 2152

bfl1
Level 1
Level 1

Recently, I've been seeing a lot of 2152 ICMP Flood traffic generated from workstations to a DNS/Active Directory server. I checked the workstations and they are clean of virus/trojan/malicous users/etc..., I enabled packetcapture, but see nothing unusual in etherreal. Maybe someone can help analyze the packet?

Thanks

2 Replies 2

klwiley
Cisco Employee
Cisco Employee

Sure, if you would forward the packet to me I would be glad to take a look at it. (klwiley@cisco.com)

You mention that you are seeing the traffic from the workstations to the server. How many workstations are involved? Are they all on the same network segment?

You also say you ttok a look at the worksations, but did you also give the serve in question a once over?

KLW

lwierenga
Level 1
Level 1

Don't believe this would be virus/trojan...because it is only banging against one server. drop down to a command prompt on the WS and issue the netstat -a command and look at what ports/protos are open, and look for the port that is using ICMP. This should get you where you want to go? Let me know. Thanks.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: