Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Has anyone else seen an excessive amount of ESP probes being sent to every public IP address . Makes me think there's a new exploit out. Check logs on the routers. Haven't ever in past 20 years seen this much probing using ESP packets. Just a head...
Doing some deep dive testing into LPTS for ddos/security/exploit reasons and came across what I consider some shortcomings. Love to hear other people's opinions/test results! I'm not sure if I'm missing something or this is the way it is intended.For...
I know this, I was posting because normally when there's a lot of traffic of a certain protocol or even a tcp port number or udp packets that match a certain pattern, it is an indication of a new exploit or ddos method. It is not affecting us in any ...
We do not use DMVPN. All of these packets are dropped by our ACLs.. It's just very strange that all of a sudden on Nov 9 we are seeing ESP across the board to IPs that should never receive anything, plus all the downstream customer IPs are receiving ...
It's not one device. We have a large network on the internet (service provider) and I'm seeing this across all devices , basically someone's probing the entire internet with ESP packets (seeing it hit all of our router public IPs, loopbacks, etc.). ...
It's just the way the platform works, maybe something on the module is sending data to the other module svi when the vlan isn't configured, or you have a trunk port with no allowed vlan (i.e. allows all), or VSL or something of the sort. Do you have ...
Most likely because that VLAN is configured on that module (i.e. some port on the module has this vlan configured) somewhere and not on the others. If you don't need massive mac addr scale, the whole platform works better when the macs are synchron...