<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Bug in syslog with l4port anomaly-protection enabled in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/bug-in-syslog-with-l4port-anomaly-protection-enabled/m-p/55114#M15846</link>
    <description>Hello Drew,&lt;BR /&gt;
&lt;BR /&gt;
Thanks fot your feedback. Indeed i looked at the RFC and it says clearly that it may use any source port to deliver the message. But this means that i cannot use both the&lt;I&gt; ip-security l4port &lt;/I&gt;and the syslog in my configuration. &lt;BR /&gt;
&lt;BR /&gt;
Maybe in a future XOS firmware release can this be worked out in order to use both the syslog and the protocol anomaly protection (when the UDP Source Port number = UDP Destination Port number) ?&lt;BR /&gt;
&lt;BR /&gt;
Best regards,&lt;BR /&gt;
&lt;BR /&gt;
Teodor</description>
    <pubDate>Tue, 12 Jan 2016 19:15:00 GMT</pubDate>
    <dc:creator>Teodor_Fuica</dc:creator>
    <dc:date>2016-01-12T19:15:00Z</dc:date>
    <item>
      <title>Bug in syslog with l4port anomaly-protection enabled</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/bug-in-syslog-with-l4port-anomaly-protection-enabled/m-p/55112#M15844</link>
      <description>Hello all,&lt;BR /&gt;
&lt;BR /&gt;
i had this ip-security configuration on one of the x440-24t switches that had the syslog server configured on one of the ports :&lt;BR /&gt;
&lt;BR /&gt;
&lt;I&gt;enable ip-security anomaly-protection ip&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;enable ip-security anomaly-protection l4port&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;enable ip-security anomaly-protection tcp flags&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;enable ip-security anomaly-protection tcp fragment&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;enable ip-security anomaly-protection icmp&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;enable ip-security anomaly-protection notify log&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;enable ip-security anomaly-protection notify cache&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;configure ip-security anomaly-protection notify cache 100&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;configure ip-security anomaly-protection notify trigger on 5&lt;/I&gt;&lt;BR /&gt;
&lt;BR /&gt;
Also i had configured on another x440-24p switches to log to the same syslog server :&lt;BR /&gt;
&lt;BR /&gt;
&lt;I&gt;configure syslog add 192.168.40.141:514 vr VR-Default local0&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;enable log target syslog 192.168.40.141:514 vr VR-Default local0&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;configure log target syslog 192.168.40.141:514 vr VR-Default local0 filter DefaultFilter severity Info&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;configure log target syslog 192.168.40.141:514 vr VR-Default local0 match Any&lt;/I&gt;&lt;BR /&gt;
&lt;I&gt;configure log target syslog 192.168.40.141:514 vr VR-Default local0 format timestamp seconds date Mmm-dd event-name condition severity priority host-name tag-name&lt;/I&gt;&lt;BR /&gt;
&lt;BR /&gt;
But the problem is that the x440-24p switch is sending the log to the syslog server using the same UDP source port as the destination UDP port :514.&lt;BR /&gt;
&lt;BR /&gt;
Please see in the attached log :&lt;BR /&gt;
&lt;BR /&gt;
&lt;I&gt; L4 port anomaly detected on port 17 vlan Default: SMAC=00:04:96:98:23:C9 DMAC=00:11:32:1F:29:9F SIP=192.168.40.242 DIP=192.168.40.141 SPORT=514 DPORT=514 ip protocol [17] pkt length [301]&lt;BR /&gt;
&lt;BR /&gt;
Definitely this is a bug and should be resolved in the next XOS release. Is the same  "trap" as other network devices might have like printers for example using the same source port as the destination port.&lt;BR /&gt;
&lt;BR /&gt;
I am using the 16.1.2.14 XOS release.&lt;BR /&gt;
&lt;BR /&gt;
Best regards,&lt;BR /&gt;
&lt;BR /&gt;
Teodor&lt;BR /&gt;
&lt;BR /&gt;&lt;/I&gt;</description>
      <pubDate>Fri, 08 Jan 2016 21:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/bug-in-syslog-with-l4port-anomaly-protection-enabled/m-p/55112#M15844</guid>
      <dc:creator>Teodor_Fuica</dc:creator>
      <dc:date>2016-01-08T21:39:00Z</dc:date>
    </item>
    <item>
      <title>RE: Bug in syslog with l4port anomaly-protection enabled</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/bug-in-syslog-with-l4port-anomaly-protection-enabled/m-p/55113#M15845</link>
      <description>Hi Teodor,&lt;BR /&gt;
I just want to make sure I understand your concern.  Is there something we're doing that doesn't fit the "MAY use any source UDP port for transmitting messages" statement in &lt;A href="https://tools.ietf.org/html/rfc5426" target="_blank" rel="nofollow noreferrer noopener"&gt;RFC5426&lt;/A&gt;?&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;3.3.  Source and Target Ports&lt;BR /&gt;
Syslog receivers MUST support accepting syslog datagrams on the well-known UDP port 514, but MAY be configurable to listen on a different port.  Syslog senders MUST support sending syslog message datagrams to the UDP port 514, but MAY be configurable to send messages to a different port.  Syslog senders MAY use any source UDP port for transmitting messages.&lt;/BLOCKQUOTE&gt;Thanks,&lt;BR /&gt;
-Drew&lt;BR /&gt;</description>
      <pubDate>Sat, 09 Jan 2016 00:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/bug-in-syslog-with-l4port-anomaly-protection-enabled/m-p/55113#M15845</guid>
      <dc:creator>Drew_C</dc:creator>
      <dc:date>2016-01-09T00:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: Bug in syslog with l4port anomaly-protection enabled</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/bug-in-syslog-with-l4port-anomaly-protection-enabled/m-p/55114#M15846</link>
      <description>Hello Drew,&lt;BR /&gt;
&lt;BR /&gt;
Thanks fot your feedback. Indeed i looked at the RFC and it says clearly that it may use any source port to deliver the message. But this means that i cannot use both the&lt;I&gt; ip-security l4port &lt;/I&gt;and the syslog in my configuration. &lt;BR /&gt;
&lt;BR /&gt;
Maybe in a future XOS firmware release can this be worked out in order to use both the syslog and the protocol anomaly protection (when the UDP Source Port number = UDP Destination Port number) ?&lt;BR /&gt;
&lt;BR /&gt;
Best regards,&lt;BR /&gt;
&lt;BR /&gt;
Teodor</description>
      <pubDate>Tue, 12 Jan 2016 19:15:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/bug-in-syslog-with-l4port-anomaly-protection-enabled/m-p/55114#M15846</guid>
      <dc:creator>Teodor_Fuica</dc:creator>
      <dc:date>2016-01-12T19:15:00Z</dc:date>
    </item>
    <item>
      <title>RE: Bug in syslog with l4port anomaly-protection enabled</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/bug-in-syslog-with-l4port-anomaly-protection-enabled/m-p/55115#M15847</link>
      <description>Hi Teodor,&lt;BR /&gt;
Let me ask around about this - going to leave the thread marked "In Progress" for now.&lt;BR /&gt;
&lt;BR /&gt;
-Drew&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Jan 2016 19:15:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/bug-in-syslog-with-l4port-anomaly-protection-enabled/m-p/55115#M15847</guid>
      <dc:creator>Drew_C</dc:creator>
      <dc:date>2016-01-12T19:15:00Z</dc:date>
    </item>
    <item>
      <title>RE: Bug in syslog with l4port anomaly-protection enabled</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/bug-in-syslog-with-l4port-anomaly-protection-enabled/m-p/55116#M15848</link>
      <description>Hi Teodor,&lt;BR /&gt;
I think it will be best for you to &lt;A href="https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-contact-Extreme-Networks-Global-Technical-Assistance-Center-GTAC" target="_blank" rel="nofollow noreferrer noopener"&gt;open a case with GTAC&lt;/A&gt; so this can be reviewed and possibly written up as a feature request.&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Jan 2016 19:15:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/bug-in-syslog-with-l4port-anomaly-protection-enabled/m-p/55116#M15848</guid>
      <dc:creator>Drew_C</dc:creator>
      <dc:date>2016-01-12T19:15:00Z</dc:date>
    </item>
  </channel>
</rss>

