route loop causes USG2100 cpu-usage abnormal and internet accessing slow

Publication Date:  2013-08-31 Views:  399 Downloads:  0
Issue Description

As shown above, accessing internet through USG2100 is slow.
Alarm Information
1. cpu-usage of USG2100 is 99%
2. There are warning messages in logbuffer as below:
%Mar 22 10:36:23 2013 USG2120BSR SEC/4/ATCKDF:AttackType:Udp flood attack; Receive Interface: Ethernet0/0/0 ; proto:UDP ; from ; to ; begin time :2013/03/22 10:35:55; end time: 2013/03/22 10:36:20; total packets: 199; max speed: 1014(packet/s);
Handling Process
1. Check the bandwidth and sessions on USG2100, and they are in normal range.
2. There are UDP attacks to, checking route to this ip address and found the nexthop is uplink device
<USG2120BSR>display fib                                                                                                  
  Route Entry Count: 1                                                                                                             
Destination/Mask   Nexthop         Flag TimeStamp     Interface       TunnelID                                               GSU  t[0]          Eth0/0/0        -                                                            
3. Checking the configuration on USG2100, found which belongs vlanif 5 should connect to interface Ethernet1/0/4 whose current state is down.
interface Vlanif5
ip address
interface Ethernet1/0/4
port access vlan 5
Ethernet1/0/4 current state : DOWN  
Line protocol current state : DOWN
4. The route on uplink device to is USG2100, but USG2100 forwards the packets back to uplink router via default route because the interface which connect is down. So, there is a route loop between USG2100 and uplink device.
5. This problem is resolved by configuring black hole route to on USG2100
Root Cause
CPU usage too high usually caused by performance insufficient:
1. bandwidth/sessions/acl rules overload
2. route loop
3. attack
4. ip duplicate
CPU usage abnormal usually caused by bandwidth/sessions/acl rules overload, route loop, attack, ip address duplicate and so on. When troubleshooting, please check them one by one.