Hi,

I've never seen this issue before and I don't find a lot of information about 
it on the Internet.

Basically what is happening is a host in a VLAN is getting flooded with http 
requests and when this happens the http requests are being unicast to all ports 
in this VLAN.

This only happens when the host is being flooded when I block the attack, 
normal traffic isn't being unicast flooded.

I would think that if this was normal unknown unicast it would always happen 
after the cam expires the mac entry...?

Has anyone heard of anything like this before?

System is a 6500 (sup 720s) /w SXI5.

thanks,
-Drew


_______________________________________________
cisco-nsp mailing list  [email protected]
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Reply via email to