DoS Attack from Omnivista IP address

Post Reply
mess2108
Member
Posts: 1
Joined: 19 Jul 2021 08:38

DoS Attack from Omnivista IP address

Post by mess2108 »

Hi all,
I noticed that randomly we see, on Omnivista Notification home, some DoS attack traps sent by some switches in the network.

I know that DoS attack could be something serious, so I try to investigate this issue. I noticed in other scenarios that the switches also send this trap when they find a duplicate IP address in their network.

The traps we are seeing are as follow:
Detected DoS attack. DoS Type: invalidip, Number of attacks: 39, Ip: [OMNIVISTA IP ADDRESS], Mac: 1025

In particular, the last devices that are sending this trap are some devices I have discovered using the entire network (e.g.: 10.10.10.1 and 10.10.10.2 discovered using the net 10.10.10.0/24), from this time, 10.10.10.1 and 10.10.10.2 are sending the trap described above twice a day.

I don't think it's a REAL DoS attack, and it seems strange that the attacker is OMNIVISTA.
Does anyone know if this could be classified as an "omnivista unexpected behavior" or something like this?

Hope I was able to explain the issue,
Thank you in advance for helping

Bye!
Post Reply

Return to “OmniVista 2500 v4.x”