According to the feedback of a branch of a financial organization, the NetStream buffer information shows that the traffic volume at an abnormal source address (such as 0.32.0.0) in the upstream direction is high. Similar problems also occur in other branches.
The NetStream buffer information shows that the traffic volume at an abnormal source address (such as 0.32.0.0) is high.
1. Obtain the alarm module and check the alarm information. The NetStream buffer information in the upstream direction of a branch shows that traffic volume at an abnormal source address (such as 0.31.0.0) is high.
2. Check the NetStream statistics about other online branches. It is found that an abnormal source address also exists in other online branches.
3. Collect device configurations and the device status. It is found that no change or state abnormality exists.4. Confirm with the customer and analyze the obtained packet header information. It is found that the BFD packets are abnormal
BFD packets adopt the label switching process. The packet type in packets sent to the sampling module is incorrect. As a result, the IPv4 header is used as an MPLS header for parsing. For details about the root cause analysis, see the attachment.
Upgrade the device version to V800R009C10SPC200.