SECE/3/ARPS_DROP_PACKET_PROADDR_LEN
Message
SECE/3/ARPS_DROP_PACKET_PROADDR_LEN:Invalid protocol address length.(ProAddressLength=[ULONG], SourceMAC=[STRING1], SourceIP=[STRING2], SourceInterface=[STRING3], DropTime=[STRING4])
Parameters
Parameter Name | Parameter Meaning |
---|---|
ProAddressLength |
Indicates the protocol address length of ARP packets. |
SourceMAC |
Indicates the source MAC address of packets. |
SourceIP |
Indicates the source IP address of packets. |
SourceInterface |
Indicates the source interface of packets. |
DropTime |
Indicates the time ARP packets were discarded. |
Procedure
- Find out the interface where the attack occurred based on the SourceInterface field in the alarm message.
- Find out the user who sent the attack packets based on the SourceMAC field in the alarm message.
- Check whether the user host runs properly; if not, the user may be the attacker. In this case, you can take measures against this, such as making the user get offline.