We are running Panorama 8.1 (Has been upgraded to 9.1.10 since the issue occurred). The Firewall itself is a 3260 running 9.1.4
We have seen a few instances in the past 3 months where a session has been detected by the Firewall that shows a simple ping has been sent from our monitoring servers (We have two which are running completely different products on each) to a Network device (Cisco Switches and Routers). What is unusual about this is the amount of data that is either being sent or received as part of this ping. See image for our Solarwinds below. In one instance 300+MB was transferred. The data transfer during each session is not equal. In the first entry the sending device only transfers 60Bytes and receives over 300MB. Sometimes it is the other way around.
I have ruled out extended pings (ping -t). The firewall shows these as a series of pings not a single event. I have also checked log files on the Cisco network devices and on the monitoring boxes. Nothing immediately stands out.
Has anyone seen this before or have any ideas.
Is the destination an internsl IP? What was the start time of that session and how many packets were transfere?
So far I assume this is a monitoring ping to a device in your network which was running for weeks already. Now that the session ended the bytes of all these pings were added together and result in these numbers that you see.
Yes it is an internal IP. The start time was 15:37. Yes it is a monitoring ping that runs every 15 seconds. I do not believe it was a series of pings added together as we are only seeing one packet sent with 334000 sent back? Also 4 pings a minute for half an hour should not equate to 300+MB.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!