cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1063
Views
0
Helpful
1
Replies

Netflow UDP Traffic With no Port

cdegroat82
Beginner
Beginner

Hello,

So as the title says - I am running Netflow - and noticing alot of UDP traffic coming in to my network with no UDP port associated to it.  It just appears with 0 for the port.  It appears to be some sort of denial of service attack from random IPs.  Is it possible to have a UDP port 0 or just push blank UDP traffic? Doesn't really make sense to me.  Any help is greatly appreciated.

1 Reply 1

Richard Burts
Hall of Fame
Hall of Fame

There must be some content in the port field of the packets. I can understand a packet with zero filled port field but makes no sense to think of blanks in the field.

It makes no sense for a valid packet to have zeros in the port field but perhaps a denial of service packet might do this.

HTH

Rick

HTH

Rick
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: