cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
951
Views
0
Helpful
1
Replies

Netflow Source and Destination Traffic 0.0.0.0

john.sumners
Level 1
Level 1

I am trying to track down some bizarre traffic.  I see 6-7Mbps at about 5000 packets per second of traffic that netflow is just showing as 0.0.0.0 source and 0.0.0.0 distination with ports of 0000.  I just have the netflow applied to one vlan interface on a 6500 where I am seeing that traffic.  I have tried removing an ACL to see if that was it, but made no change.  Any idea what that traffic is?  How can I track it down?  It is causing havoc on some wireless mesh links to the point that I had to move the mesh to a different VLAN.

1 Reply 1

gchana2011
Level 1
Level 1

Hey John,

Not sure what could be causing something like that but I'll just throw an idea out there - have you tried performing a packet capture on the problem VLAN? This should identify the source MAC(s) of the traffic and should in theory allow you to trace it back to the source.

Hope this helps.