cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
640
Views
0
Helpful
1
Replies
Highlighted
Beginner

Netflow UDP Traffic With no Port

Hello,

So as the title says - I am running Netflow - and noticing alot of UDP traffic coming in to my network with no UDP port associated to it.  It just appears with 0 for the port.  It appears to be some sort of denial of service attack from random IPs.  Is it possible to have a UDP port 0 or just push blank UDP traffic? Doesn't really make sense to me.  Any help is greatly appreciated.

1 REPLY 1
Highlighted
Hall of Fame Guru

There must be some content in the port field of the packets. I can understand a packet with zero filled port field but makes no sense to think of blanks in the field.

It makes no sense for a valid packet to have zeros in the port field but perhaps a denial of service packet might do this.

HTH

Rick

HTH

Rick
Content for Community-Ad