cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1172
Views
0
Helpful
1
Replies

Netflow UDP Traffic With no Port

cdegroat82
Level 1
Level 1

Hello,

So as the title says - I am running Netflow - and noticing alot of UDP traffic coming in to my network with no UDP port associated to it.  It just appears with 0 for the port.  It appears to be some sort of denial of service attack from random IPs.  Is it possible to have a UDP port 0 or just push blank UDP traffic? Doesn't really make sense to me.  Any help is greatly appreciated.

1 Reply 1

Richard Burts
Hall of Fame
Hall of Fame

There must be some content in the port field of the packets. I can understand a packet with zero filled port field but makes no sense to think of blanks in the field.

It makes no sense for a valid packet to have zeros in the port field but perhaps a denial of service packet might do this.

HTH

Rick

HTH

Rick
Review Cisco Networking for a $25 gift card