[c-nsp] Traffic destined to IPs that are null routed, Netflow, and you!

Phil Mayers p.mayers at imperial.ac.uk
Fri Mar 12 09:56:25 EST 2010


On 12/03/10 13:23, Drew Weaver wrote:
> Hi,
>
> I had an incident earlier this week where for "some reason" a large
> amount of traffic was being sent to an IP that wasn't routed in my
> network (was covered by the hold down).
>
> Ultimately I found the source/dest of the traffic by simply routing
> all of the unused IPs to a server, and then used tcpdump.
>
> My question is, is it normal for this 'hold down' traffic not to show
> up anywhere in Netflow?

On what platform?

It does show up in our netflow, on 6500/sup720.

That said, the "out if" index is the ifIndex of Null0, which is NOT zero.


More information about the cisco-nsp mailing list