- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
08-01-2021 09:12 PM
Hi All,
We are running Panorama 8.1 (Has been upgraded to 9.1.10 since the issue occurred). The Firewall itself is a 3260 running 9.1.4
We have seen a few instances in the past 3 months where a session has been detected by the Firewall that shows a simple ping has been sent from our monitoring servers (We have two which are running completely different products on each) to a Network device (Cisco Switches and Routers). What is unusual about this is the amount of data that is either being sent or received as part of this ping. See image for our Solarwinds below. In one instance 300+MB was transferred. The data transfer during each session is not equal. In the first entry the sending device only transfers 60Bytes and receives over 300MB. Sometimes it is the other way around.
I have ruled out extended pings (ping -t). The firewall shows these as a series of pings not a single event. I have also checked log files on the Cisco network devices and on the monitoring boxes. Nothing immediately stands out.
Has anyone seen this before or have any ideas.
Thanks
08-01-2021 10:52 PM
Hi @DanielC_LCC
Is the destination an internsl IP? What was the start time of that session and how many packets were transfere?
So far I assume this is a monitoring ping to a device in your network which was running for weeks already. Now that the session ended the bytes of all these pings were added together and result in these numbers that you see.
08-01-2021 11:04 PM
Hi @Remo
Yes it is an internal IP. The start time was 15:37. Yes it is a monitoring ping that runs every 15 seconds. I do not believe it was a series of pings added together as we are only seeing one packet sent with 334000 sent back? Also 4 pings a minute for half an hour should not equate to 300+MB.
Thanks
08-01-2021 11:46 PM
This IP where the ping is sent to, is this IP even active or is it a device that no longer exist?
08-02-2021 12:14 AM - edited 08-02-2021 12:14 AM
Do you allow ping in both directions?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!