Packet floods

mmolyneux
New here

Packet floods

Hi.

 

I've just started to look at Air Marshal and I'm seeing HUGE amounts of single-source & multi-source packet floods. (see image below for a small sample from both air marshal and the logs). Might not be a simple answer... but am I being attacked!?

 

flood2.jpgflood1.jpg

1 Reply 1
PhilipDAth
Kind of a big deal
Kind of a big deal

Yes, I would say it is an attack looking at the messages.  There are a large number of beacon and probe packets.

https://documentation.meraki.com/MR/Monitoring_and_Reporting/Common_Wireless_Event_Log_Messages#Air_...

 

You are unlikely to be able to do much about it.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels