<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: DOS protect log message in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dos-protect-log-message/m-p/26589#M3623</link>
    <description>Maybe this will help... here is  a snip of log messages from a core IPTV switch that had an EAPS ring event and there was a flood of mcast joins when ring fails over which is processed by the cpu.  You see the port affected and the ip address that was generating the traffic.  In our case this did not affect network traffic as this was only mcast joins.... If this were a flood or broadcast storm where the links would be over run then it would still create and acl but it would not stop the traffic on the interface it only protects the traffic from over whelming the cpu... &lt;BR /&gt;
&lt;BR /&gt;
02/17/2016 14:36:41.77 &lt;I&gt; MSM-A: Removed ACL from port 2:2, srcIP 172.16.150.60 to destIP 0.0.0.0, protocol udp02/17/2016 14:36:37.12 &lt;I&gt;&lt;BR /&gt;
 MSM-A: Notify-threshold for L3 Protect packet count of 3500 reached&lt;BR /&gt;
02/17/2016 14:36:36.15 &lt;I&gt; MSM-A: Added an ACL to port 2:2, srcIP 172.16.150.60 to destIP 0.0.0.0, protocol udp&lt;BR /&gt;
02/17/2016 14:36:36.05 &lt;I&gt; MSM-A: Notify-threshold for L3 Protect packet count of 3500 reached&lt;BR /&gt;
02/17/2016 14:36:35.06 &lt;I&gt; MSM-A: No traffic pattern found&lt;BR /&gt;
02/17/2016 14:36:34.97 &lt;I&gt; MSM-A: Notify-threshold for L3 Protect packet count of 3500 reached&lt;BR /&gt;
&lt;BR /&gt;
If this were a bcast storm the destination address would be the bcast address for subnet and not 0.0.0.0 ...&lt;BR /&gt;
&lt;BR /&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;</description>
    <pubDate>Thu, 18 Feb 2016 05:39:00 GMT</pubDate>
    <dc:creator>EtherMAN</dc:creator>
    <dc:date>2016-02-18T05:39:00Z</dc:date>
    <item>
      <title>DOS protect log message</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dos-protect-log-message/m-p/26585#M3619</link>
      <description>Hi, i have a problem... I see this messages in the log&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="04fcca8b86eb49d9add27434dc7d7fd4_RackMultipart20160217-25465-1oqfw99-Captura_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1693iAB1D50A2C878E274/image-size/large?v=v2&amp;amp;px=999" role="button" title="04fcca8b86eb49d9add27434dc7d7fd4_RackMultipart20160217-25465-1oqfw99-Captura_inline.png" alt="04fcca8b86eb49d9add27434dc7d7fd4_RackMultipart20160217-25465-1oqfw99-Captura_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;
&lt;BR /&gt;
I read in extreme documents but its not clear to my. in the ExtremeXOS 16.1 EMS Message Catalog i read what this messages is only informative and in the DOS protect log message article say what &lt;I&gt;"Once the threshold is exceeded, it will stop the packets from reaching the CPU"&lt;/I&gt;.&lt;BR /&gt;
So my quetion is: &lt;BR /&gt;
&lt;BR /&gt;
is there a locking action in the SW? or definitely is only information....&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Feb 2016 04:49:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dos-protect-log-message/m-p/26585#M3619</guid>
      <dc:creator>Daniel_Valera1</dc:creator>
      <dc:date>2016-02-18T04:49:00Z</dc:date>
    </item>
    <item>
      <title>RE: DOS protect log message</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dos-protect-log-message/m-p/26586#M3620</link>
      <description>Hello Daniel,&lt;BR /&gt;
&lt;BR /&gt;
Dos-protect is a simulated process that will send packets to the CPU for examination based on the amount specified in the configuration (show configuration dosprotect).  Once the configured amount is exceeded it will inform with log messages.  Dos-protect checks a specified amount of packets for patterns.  If none are found it will also notify of this in the log.  &lt;BR /&gt;
&lt;BR /&gt;
What type of locking action are you referring to?  It will help if you can provided output to "show config dosprotoect".&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Feb 2016 04:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dos-protect-log-message/m-p/26586#M3620</guid>
      <dc:creator>Hernandez__Josh</dc:creator>
      <dc:date>2016-02-18T04:54:00Z</dc:date>
    </item>
    <item>
      <title>RE: DOS protect log message</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dos-protect-log-message/m-p/26587#M3621</link>
      <description>thanks for you commets... i'm referiring to blocking complete the LAN services for about 5 seg.&lt;BR /&gt;
&lt;BR /&gt;
&lt;P class="fancybox-image"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="6120f4db6f274cb4b0b6714962d2c6de_RackMultipart20160217-62205-14crsqi-unnamed_inline.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/1043iD84E5E6E28783E6E/image-size/large?v=v2&amp;amp;px=999" role="button" title="6120f4db6f274cb4b0b6714962d2c6de_RackMultipart20160217-62205-14crsqi-unnamed_inline.png" alt="6120f4db6f274cb4b0b6714962d2c6de_RackMultipart20160217-62205-14crsqi-unnamed_inline.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 18 Feb 2016 04:54:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dos-protect-log-message/m-p/26587#M3621</guid>
      <dc:creator>Daniel_Valera1</dc:creator>
      <dc:date>2016-02-18T04:54:00Z</dc:date>
    </item>
    <item>
      <title>RE: DOS protect log message</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dos-protect-log-message/m-p/26588#M3622</link>
      <description>An important key to understanding how the DDOS to cpu works is knowing what packets are sent to the cpu versus switched in hardware.  You can run this in active mode which will create the acl on the fly and block packets it is targeting in the acl from the cpu or you can run in simulated mode (we do this) where you get same traps but no acl is created.  If you are lucky you get mac address or ip address in the info.  This does not stop a flood on your interfaces it only protects the cpu from being overrun...</description>
      <pubDate>Thu, 18 Feb 2016 04:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dos-protect-log-message/m-p/26588#M3622</guid>
      <dc:creator>EtherMAN</dc:creator>
      <dc:date>2016-02-18T04:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DOS protect log message</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dos-protect-log-message/m-p/26589#M3623</link>
      <description>Maybe this will help... here is  a snip of log messages from a core IPTV switch that had an EAPS ring event and there was a flood of mcast joins when ring fails over which is processed by the cpu.  You see the port affected and the ip address that was generating the traffic.  In our case this did not affect network traffic as this was only mcast joins.... If this were a flood or broadcast storm where the links would be over run then it would still create and acl but it would not stop the traffic on the interface it only protects the traffic from over whelming the cpu... &lt;BR /&gt;
&lt;BR /&gt;
02/17/2016 14:36:41.77 &lt;I&gt; MSM-A: Removed ACL from port 2:2, srcIP 172.16.150.60 to destIP 0.0.0.0, protocol udp02/17/2016 14:36:37.12 &lt;I&gt;&lt;BR /&gt;
 MSM-A: Notify-threshold for L3 Protect packet count of 3500 reached&lt;BR /&gt;
02/17/2016 14:36:36.15 &lt;I&gt; MSM-A: Added an ACL to port 2:2, srcIP 172.16.150.60 to destIP 0.0.0.0, protocol udp&lt;BR /&gt;
02/17/2016 14:36:36.05 &lt;I&gt; MSM-A: Notify-threshold for L3 Protect packet count of 3500 reached&lt;BR /&gt;
02/17/2016 14:36:35.06 &lt;I&gt; MSM-A: No traffic pattern found&lt;BR /&gt;
02/17/2016 14:36:34.97 &lt;I&gt; MSM-A: Notify-threshold for L3 Protect packet count of 3500 reached&lt;BR /&gt;
&lt;BR /&gt;
If this were a bcast storm the destination address would be the bcast address for subnet and not 0.0.0.0 ...&lt;BR /&gt;
&lt;BR /&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;&lt;/I&gt;</description>
      <pubDate>Thu, 18 Feb 2016 05:39:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dos-protect-log-message/m-p/26589#M3623</guid>
      <dc:creator>EtherMAN</dc:creator>
      <dc:date>2016-02-18T05:39:00Z</dc:date>
    </item>
  </channel>
</rss>

