A lot of unknown traffic.

My goal is to reduce traffic loads and save some money.
Now I am exporting Netflow to AdventNet Netflow Analyzer - it is helping me to understand what traffic is passing through router. It gives a lot of useful information. But, I still have a lot of traffic that I can not classify - tcp and udp, random ports, googling gives no result. I want to have some kind of Intrusion Detection or Virus Detection software. Some soft that helps me to classify unknown traffic and probably say to me : this traffic is net worm activity. Or something like that. What solution you can advice (except - Cisco MARS)?
Thank you.

you may either have signature definition .sdf install in the routers flash or have IDS module in the router (NMIDS)

Similar Messages

  • T520 a lot of unknown devices

    Hello,
    I have T520 laptop, and device  manager shows me a lot of unknown devices (~50).
    If I try to update driver of any of them, then I got the message:
    Windows found driver software for your device but encountered an error while attempting to install it.
    siFilterIP GigE Vision Filter Driver
    Insufficient system resources exist to complete the requested service
    This is not a big deal, but it irritates me.

    Yes, you are right. I guess this should be a device in the laptop, that can receive a video stream from a network attached camera. I never connected such a camera directly to my computer, but I suppose I could connect my laptop to a network, which has one. Do you think this could be a problem? Now I start wondering, if my laptop is supposed to have such a device that can receive a video stream from network? If not, then situation is weird. Also I have VirtualBox installed, and it adds some network interfaces to host. Maybe this is some feature of VirtualBox, so I could stream video from my webcam to virtual machine? I should investigate this.

  • Oracle oleDB generates lots of network traffic than Microsoft Oledb

    Hi,
    When calling the same stored proc. that returns a ref cursor, Oracle Oledb (1.34 MB) generates alot of network traffic than Microsoft Oledb (0.06 MB). The statistic is gathered using Windows 2000 Network Monitoring tools.
    Calling the same stored proc. that returns a ref cursor
    Oracle OleDB Microsoft Oledb
    Byte Received: 1408026 (1.34 M) 71032 (0.06 M)
    Byte Sent: 306468 (0.29M) 69914 ( 0.067M)
    Frame: 1263 414
    Network Utilization: 6%-14% 1%-3%
    Anyone know why is this case?
    Joe

    When working with ADO and VB6, I looked at the database server with SQL Trace and found that each dynamic SQL statement was parsed twice per execution. REF CURSORs certainly require several network round-trips in order to retrieve schema information for the dataset to be created. This behaviour probably increases network load.
    Unfortunately, I have not found any description of Oracle's OLEDB implementation. Hopefully, things will get better with the new, native OleDb data adapter.
    /Armin
    Previous post:
    multiple parsing of SELECTs O/S : N/A POST: REPLY (W/QUOTE)
    Author : Armin Type : N/A
    Date : Apr 7, 2001 12:51 PT
    System: OLEDB provider 8.1.7, server 8.1.7.
    Our VB code dynamically assembles SELECT statements and fetches recordsets with ADO function Recordset::Open. SQL TRACE shows that those SELECTs are parsed twice per execution. SELECTs embedded in stored procedures are parsed only once during the SP's life time (but then the stored procedure call itself is parsed once per execution).
    Parsing twice per execution consumes a lot of CPU. REF Cursors might reduce parsing but cause additional network roundtrips.
    How could I reduce the parse count?

  • Getting a lot of unknown certificate notices in Safari. What's up?

    In the last month, I've been getting "unknown certificate" notices from Safari. I don't see anything wrong with the certificate details, but I'm not sure what to look for. The notices tell me that without the certificate, I won't know if it is a trusted site: the purpose of the certificates I guess. None of the notices were from first time sites. i.e. I was going there on purpose, not through any links, etc. What's up? Should I be concerned? How do I detect if I SHOULD be concerned by information in the details of the certificate?  Russell

    First, the process by which the Mac OS checks the validity of root SSL certificates doesn't currently work behind an authenticating proxy, such as those used on some enterprise networks. If you're in that situation, contact your network administrator.
    Are the current date (including the year) and time shown on your system clock? If not, correct them and try again.
    Otherwise, launch the Activity Monitor application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ If you’re running Mac OS X 10.7 or later, open LaunchPad. Click Utilities, then Activity Monitor in the page that opens.
    Select All Processes from the menu in the toolbar, if not already selected. Enter "ocspd" (without the quotes) in the "Filter" text field. Is a process with that name listed?
    If not, select Go ▹ Go to Folder… from the Finder menu bar. In the text box that opens, enter
    /var/db/crls
    From the folder that opens, move these two files to the Trash:
    crlcache.db
    ocspcache.db
    You’ll be prompted for your administrator password when you do this. Then reboot, empty the Trash, and try again.

  • My MacBook Storage is suddenly occupied by lots of unknown stuffs. What should I do?

    So this is what happened to my MacBook only after a month usage. I didn't download any space-wasting applications.
    Anyone please help me to figure out what happened here.
    Thanks

    Your startup volume is almost full. First, reboot. That will temporarily free up some space. According to Apple documentation, you need at least 9 GB free for normal operation. You also need enough space left over to allow for growth of your data.
    Use a tool such as OmniDiskSweeper to explore your volume and find out what's taking up the space.
    Proceed further only if the problem hasn't been solved.
    ODS can't see the whole filesystem when you run it just by double-clicking; it only sees files that you have permission to read. To really see everything, you have to run it as root.
    First, back up all data if you haven't already done so. No matter what happens, you should be able to restore your system to the state it was in at the time of that backup.
    Launch the Terminal application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ If you’re running Mac OS X 10.7 or later, open LaunchPad. Click Utilities, then Terminal in the page that opens.
    After installing ODS in the Applications folder, drag or copy — do not type — the following line into the Terminal window, then press return:
    sudo /Applications/OmniDiskSweeper.app/Contents/MacOS/OmniDiskSweeper
    You'll be prompted for your login password, which won't be displayed when you type it. You may get a one-time warning not to screw up.
    I don't recommend that you make a habit of this. Don't delete anything while running ODS as root. When you're done with it, quit it and also quit Terminal.

  • Why does Letchworth State Park have no service at all.  High traffic area.  Lots of tourists.

    Letchworth State Park in NY is call the Grand Canyon of the east.  It has 3 high falls and a huge canyon.  Very Popular tourist attraction.  Lots of people traffic.  Dangerous area.  14 year old fell off a 200 foot cliff last week and died.  How did they summon help.  Not through Verizon.  No service at all through out 80% of the park.

    The reason is regulatory interference. For many years people who live in the Adirondack Park Corridor also had zero cell service. Most do not even today. But Verizon does have two towers there now.
    Slow progress. In fact they are made to look like big trees because the residents did not want the towers showing.
    In your location it is probably the same issues. Towns and villages or even New York State  just won't approve placement of towers.
    It is the same all over.
    Remember the state putting emergency phones on highways and other areas that had no cell service? Then spent millions removing them? Then put them back for millions more tax dollars due to people yelling for their return.

  • BT is blocking specific traffic - Connection probl...

    I started having this problem about two weeks ago, after multiple phonecalls to BT and a couple of emails nothing has been done, so hopefully someone on the forum can help.
    The problem is the BT server that my hub connects to runs software to block specific traffic, I assume this is handy for restricted torrents or illegal downloads. But what it's blocking is a game called EVE Online, I used to play this game without a single problem until about two weeks ago. I logged in one day and the lag was unbearable, mainly due to the fact BT is blocking around 90% of packets that are sent to me. As I said, I used to be able to play no problem, but now I can't even go on for 2 minutes before I get kicked.
    I've confirmed with the EVE support team that BT is causing the problem, EVE uses UDP and it only requires a packet loss of 5 consecutive packets before the game disconnects you. This may not seem like a lot, but due to the nature of it, any more than 5 packets can cause major problems in the game, so they just disconnect you. A friend of mine also had this problem, but to a lesser extent, but it did span accross multiple games, he has since then switched to another broadband provider which I will not name, and hasn't had the issue since. In EVE, recently BT have been known to block traffic, I'm not the first to ask EVE support for assistance on the matter, so they weren't strangers to the problem.
    I've ran a program called Ping Plotter to the EVE server, for those of you unaware Ping Plotter is a useful tool to (as the name suggests) Plot the latency (ping) of your connection to the server. PP also records packet loss and the exact route the client is using to connect to the server. The results average about 90% packet loss, Below are the results of PP.
    500 trace count, 1 second per trace.
    Packet loss is highlighted in RED
    BT IP's are highlighted in BLUE
    EVE IP's are highlighted in GREEN
    Target Name: srv200-g.ccp.cc
    IP: 87.237.38.200
    Date/Time: 21/01/2014 2:41:46 AM to 21/01/2014 2:50:12 AM
    Hop Sent Error    PL%  Min Max Avg  Host Name / [IP]
     1   500      0      0.0      1   34    2  BThomehub.home [192.168.1.254]  PC TO HUB 
     2   500    423    84.6    9   57   21  esr19.edinburgh8.broadband.bt.net [213.1.130.142] HUB TO BT
     3   500    474    94.8   10  149  26  [213.1.130.125]
     4   500    480    96.0   18   66   29  [213.1.69.74]
     5   500    481    96.2   19   63   31  [31.55.165.77]
     6   500    476    95.2   19   71   35  [31.55.165.107]
     7    14     11     78.6    18   53   29  acc1-10GigE-4-1-3.mr.21cn-ipp.bt.net [109.159.250.114]
     8   133    126    94.7   29   62   47  core2-te0-13-0-14.ilford.ukcore.bt.net [109.159.250.46]
     9   262    238    90.8   27   69   47  peer3-te0-1-0-7.telehouse.ukcore.bt.net [109.159.254.251]
    10  500    443    88.6   25    74   40  ccpgames.com [195.66.226.23]
    11  500    465    93.0   25    69   42  te-d2-e2.ccp.cc [87.237.37.246]
    12  500    422    84.4   25    77   38  srv200-g.ccp.cc [87.237.38.200]
    As you can see, that is completely unacceptable. The connection between my PC to my HUB is perfect, from the HUB to BT is where things go pearshaped.
    Onto another note, the three times I've phoned, I've spoken to someone reading from a card. What I mean by that is they haven't got a clue what they're speaking about. They are denying there is a problem because 'ping google' works fine. the first time I was redirected to the tech support, but then found out I wasn't paying for the service so I couldn't use it. The second time the advisor hung up on me when I requested to speak to her supervisor, and the third I hung up because the advisor claimed BT broadband isn't designed to support online gaming, and he said a 90% packet loss is to be expected when online gaming, alright then.
    Any help whatsoever on this issue is greatly appreciated, If I've missed anything out just ask for it and i'll post it
    Thanks.

    What home hub model do you have and have you tried rebooting it? Lots of UDP traffic can be difficult for some routers to handle due to inbuilt firewall, an older router or possibly a router thats starting to have problems might cause issues(Dust blocking airflow slowing the processor down) like this due to load on the processor of the router(These things normally have very slow processors). Have you tried running extended ping tests ? I'd try ping -n 1000 www.google.co.uk and ping -n 1000 www.bbc.co.uk additionally try using ping -l 750 -n 1000 www.google.co.uk and ping -l 750 -n 1000 www.bbc.co.uk , What package are you on are you sure you're not on a package with traffic shaping? If the devices BT use to shape traffic dont understand what eve is it might assume its P2P related and throttle it? A glasnost test should help there. But the package you are on should be Totally unlimited rather than just unlimited and was introduced from sometime around Feb last year I believe. If you are on an older contract you are probably being traffic shaped. Additionally its best to concentrate on Packet loss to servers rather than to routers. Backbone routers are often setup to depriorize icmp traffic directed to their own addresses except from servers used to manage them, concentrating on packet loss to intermediate devices is often a red herring.
    There are various utilities out there that can test a tcp or UDP in a similar sort of way to ping, however the remote servers if they are protected by firewalls and IDP systems might detect that as an anomoly and block it as a possible attack.

  • How to differentiate defects in QA32 using Traffic light

    Hi QM Experts,
    My scenario is,
    How to set Monitor control in QA32 screen.
    In the QA32 screen list of inspection lot will be displayed, for that inspection lot if any characteristics value is within / outside the limit, ie. for example specification is A2,R3 and i found 1 defect also defect is 4.
    how to differentiate this with the help of Traffic light.
    Regards,
    Krish

    Hi Krish,
    As per best of my information, the traffic lights in QA32, depends on the Start Sate and End Date of the inspection lot.
    If the End Date is not passed away (the current date is between the Start Date and End Date) it will be yellow.
    If the End Date is Passed away and UD is not not for the Lot then the traffic light will be RED and as soon as UD done at any date/stage the light will become Green.
    Conclusively, the light can't be linked with Defect Codes.
    Regards,
    Shyamal

  • Adobe Reader appears as Product Version Unknown

    I tried to list the installed Adobe Reader Versions on all of our PCs.
    It produces a lot of "Unknown" versions. I assume it is a subverison specific Version 9.0. It is installed within directory C:\Programme\Adobe\Reader 9.0\Reader but on other PCs the Version 9.0.0 is displayed in the list.
    How can I solve such an inconsistancy?
    Klaus

    BachmannK,
    It appears that in the past few days you have not received a response to your
    posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Visit http://support.novell.com and search the knowledgebase and/or check all
    the other self support options and support programs available.
    - You could also try posting your message again. Make sure it is posted in the
    correct newsgroup. (http://forums.novell.com)
    Be sure to read the forum FAQ about what to expect in the way of responses:
    http://forums.novell.com/faq.php
    If this is a reply to a duplicate posting, please ignore and accept our apologies
    and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://forums.novell.com/

  • UDP broadcast traffic on port 4554 from Wireless Access Points

    Hello,
    I am seeing a lot of broadcast traffic coming from my AP541N-A-K9 access points at port 4554/UDP . I have 5 of these in a cluster. I cant seem to find anything in the manual in regards to this port traffic. Any help is apprecieted

    Hi
    I found this reference for this. As per this it is used for "internal use"
    https://www.cisco.com/assets/sol/sb/WAP561_Emulators/WAP561_Emulator_v1.0.4.4/device_info.html
    HTH
    Rasika
    **** Pls rate all useful responses ****

  • WAAS Rjct Resources and conditions for asymmetric traffic

    Hello,
    I have a customer network of 30 WAE's connected to an MPLS cloud. Interception method is inline for all WAE, and WCCP for NM-WAE.
    Of those WAE's (running 4.1.1c), I have 3 that are connected in Datacenters, as such they are expected to receive most of the traffic and have been dimensioned as OE7341 appliances.
    It is my impression that this network statistics are not as good as they should be: Some of the optimizations factor are at 1.2 or 1.3X and most are simply 1.0X.
    My impression is that there is a lot of passthrough traffic, and although some of it is configured as so on the application policies, when I check statistics pass-through on several WAE's on the network I see that the Rjct Resources is very high in a particular WAE in a Datacenter - that has a 7341 Box (12Gb RAM!) - and I also do get non-zero counters on other boxes.
    Is there any way to see on a given moment how many connections are going through the box so that I understand if I'm really facing a box capacity issue? The initial shows I did didn't look as there were that many connections running through the box, but if I checked them live I saw about 65 Rjct Resource connection at a given time.
    Can anybody shed some light on this particular statistic?
    sghmansin--17w#
    sh statistics pass-through
    Outbound
    PT Client:
    Bytes 4081578138946
    Packets 11567591648
    PT Server:
    Bytes 8833662508567
    Packets 13797553929
    Active Completed
    Overall 0 0
    No Peer 7 141742513
    Rjct Capabilities 0 0
    Rjct Resources 65 273669865
    App Config 6 25610854
    Global Config 0 0
    Asymmetric 1 1597096
    In Progress 97 453847516
    Intermediate 0 0
    Overload 0 0
    Internal Error 0 478
    App Override 0 0
    Server Black List 0 150553
    AD Version Mismatch 0 0
    sghmansin--17w#
    One other observation is that pass-through through asymetric is also very frequent. Given that the customer is mostly using inline interception, even if a connection comes through a WAN/LAN interface pair and exits through another, the optimization should still be done.
    The datacenter designs are dual-homed active/passive, and traffic goes through the same (and only) WAE box. The customer assures me that there is no asymetrical traffic.
    Can anybody explain to me how is the decision made to mark a given flow as asymmetrical (and them pass-through it)?
    Thanks
    Gustavo Novais

    Hi Dan, Thank you for your reply.
    That show was just from one of the boxes, in this case on the Datacenter.
    For instance I also see asymetricals in NM-WAE's configured for WCCP. But the number is not that substantial, which makes me believe the interception is well configured (unfortunately the routers are managed by a third party, and I am yet to have access to their config).
    All boxes on this network have Enterprise License activated.
    How can I check on a given moment all connections count on the box? is there any MIB oid pollable to check that?
    Do passthrough connections count to the overall limit?
    While doing the diagnostics on the WAAS devices there was in deed a WAAS device marked as having asymetrical traffic, but many others have PT Asym connections and have not been marked as such by the diagnostics?
    How does the diagnostic work? Is it a instantaneous dianostic (i.e. checks connection table at time T to see if any of the current connections is PT Asym )?
    If on the far end of a connection we do have an asymetrical network topology, does the near end also mark the same connection as PT Asym, or will it simply say No Peer?
    thanks
    Thanks

  • Unknown error - will not sync with iTunes

    My 80gb video iPod worked fine until yesterday. Now every time I try to sync with iTunes an unknown error occurs and it won't update from the Library. Have tried everything suggested, even restoring and have consequently lost all music from the iPod after the letter B. I updated the iPod with the latest software it suggested, was wondering if that could have anything to do with it, or what I could do about it.
    Thank you.
    Dell Inspiron 6000   Windows XP Pro  

    Could you quote for me what the error message says?
    Since there are a lot of "unknown error" numbers out there with syncing (-36, -50, -69, -39, -48, etc.), it would help to know what is the exact error number that you are getting.
    Thanks for the info!
    -Kylene

  • When is map traffic data updated?

    I just turned on my iPhone to check today's traffic. It was surprisingly green - in fact, it looked a lot like the traffic at 10 PM last night. Flipped to satellite view and 101 is very very red - flipped back, map view is green. Dragging the view around and turning traffic on and off had no effect; it only updated after I went to a different bookmark and came back.
    Looks like traffic data is being cached, which makes it a bit useless. It should at least refresh if I flip it on and off again.

    I am having this same problem, but I think my husband and I figured it out.
    About 11:30am today, I checked traffic in the Los Angeles area and it was red all over. I panicked and called some business associates to let them know we were in for a bumper to bumper ride to our meeting. It turns out that the traffic moved at or above speed limit the whole way.
    I looked at my traffic map on my iPhone again around 4pm and the traffic was exactly the same as it was at 11:30am (very red).
    When I got home tonight I mentioned it to my husband. We did a little investigation and found that the problem is on Google's end. Shortly before posting this, we went to maps.google.com and the traffic was exactly as it was reported on my iPhone. My husband also checked it on his Blackberry and it was the same as on my iPhone and on Google's website. Then we went to sigalert.com, the map was all green.
    So - it's our guess that Google sometimes has glitches in their reporting. The traffic report that they have on their site right now is probably from this morning's rush hour commute. I hope they resolve it soon. That's a critical feature for me.

  • Exceeding IMAP-Traffic with Leopard Mail

    I'm seeing some weird network traffic on my mailserver over IMAPS. I configured Mail.app to fetch my mail via IMAPS from my cyrus imap server. Since some weeks I get traffic warning from my provider. The traffic exceeding the former values about 2 or 3 times. I tracked this down with ntop on my server and see that there is a lot of IMAPS traffic. About 780 MB within a few ours to my MacBook with Leopard.
    So I assume that the new Mail.app is behaving different then Mail.app in Tiger. The exceeding traffic seems to start when I swiched to Leopard.
    Can anyone confirm this?

    Yes you are right. The reason is simple and quite sad
    Let assume you want to send a mail with an attachment of 1 MB size.
    First you send the mail via SMTP: upload traffic 1 MB so far. Then your Sent Items folder gets synchronized: another instance of the message is downloaded: 2 MB total.
    Then your All mail folder gets synchronised: that includes All mail, hence Sent Items as well: another 1 MB download will be generated.
    Summary:
    Sending 1 MB invokes the upload of 1 MB and the download of 2 MB.
    If you receive an email of 1 MB size: downloading to Inbox (1 MB), downloading to All Mail (1 MB)
    Summary:
    Receiving 1 MB invokes the download of 2 MB.
    The problem is related to two different issues: one with the sending-sent items relationship, the other is the missing unsubscribe option for IMAP (such function only works for Exchange).
    Best Regards
    Gergő

  • Firefox generates a lot of webtraffic. What may be wrong?

    My Firefox regularly generates a lot of web-traffic. While not page is apparently downloading, it continuously downloads something with speed around 50-60,000 B/sec, as the Resource Monitor shows. When I make it work offline, the traffic stops. I don't think it is updates. I can't really say more as I have no clue what may be the reason. Thanks.

    Clear the cache and the cookies from sites that cause problems.
    "Clear the Cache":
    * Tools > Options > Advanced > Network > Offline Storage (Cache): "Clear Now"
    "Remove Cookies" from sites causing problems:
    * Tools > Options > Privacy > Cookies: "Show Cookies"
    Start Firefox in <u>[[Safe Mode]]</u> to check if one of the extensions is causing the problem (switch to the DEFAULT theme: Firefox (Tools) > Add-ons > Appearance/Themes).
    *Don't make any changes on the Safe mode start window.
    *https://support.mozilla.com/kb/Safe+Mode

Maybe you are looking for

  • When I try to play a movie on my ipod, it reboots! Help!

    So I put a movie on my iPod 4th Generation Nano (mp4 format) from iTunes, and it's on my iPod, but when I try to play it, the Apple logo appears and the iPod reboots. This happens every time. I have plenty of memory left over, so I'm not out of it. T

  • Bobj is undefined error while debugging a web application

    Hello, I am developing an asp.net web application in which I display a report, and testing it by using a sample (dummy) report that's saved on the computer's hard drive.  In design mode, the report displays properly, when when I try to debug the site

  • Re: Zero AR in Billing

    Hello Friends, I have a scenario. I would like to create a order to cash cycle in such a way that the net value of the item in billing is Zero. I.e basically no AR is created in Billing document . Can you help me what steps will be required in order

  • Connecting MIDI keyboard to Mac Mini

    Are there cables available to connect a MIDI keyboard to the Mac Mini either via USB or Fireware? Or is there an adapter that goes MIDI to one of the said ports? Thanks! J

  • IOS 8.2 update disabled messages & phone keeps shutting off

    I have an iPhone 5S.  Capacity is 12.5 GB with 1.4 available. I just updated today with the 8.2 ios.  My phone has automatically shut itself off too many times to count.  Literally it has shut itself off 4 times since I started writing this....Additi