I have a Cisco 2500 sitting between two Ethernet subnets. A device on one subnet is generating a high level of UDP broadcast traffic to the address
239.192.2.64. This traffic is appearing on both subnets. My understanding is that the Cisco router does not normally forward these broadcasts without an IP helper address. I have not configured the helper address, and I have run the command 'no ip forward-protocol udp' with no change in behavior.I've included a portion of the Ethereal trace below. Can anyone tell me how to block this traffic from coming through the router?
Thanks, Joe
No. Time Source Destination Protocol Info
1 2007-08-13 10:52:58.186418 192.168.11.10 239.192.2.65 ENIP Connection: ID=Frame 1 (66 bytes on wire, 66 bytes captured)Arrival Time: Aug 13, 2007 10:52:58.186418000
Time delta from previous packet: 0.000000000 seconds
Time since reference or first frame: 0.000000000 seconds
Frame Number: 1
Packet Length: 66 bytes
Capture Length: 66 bytes
Protocols in frame: eth:ip:udp:enip
Coloring Rule Name: Low TTL
Coloring Rule String: ip.ttl < 5
Ethernet II, Src: Allen-Br_2b:0d:9a (00:00:bc:2b:0d:9a), Dst:
01:00:5e:40:02:41 (01:00:5e:40:02:41)Destination: 01:00:5e:40:02:41 (01:00:5e:40:02:41)
Address: 01:00:5e:40:02:41 (01:00:5e:40:02:41)
.... ...1 .... .... .... .... = Multicast: This is a MULTICAST frame
.... ..0. .... .... .... .... = Locally Administrated Address: This is a FACTORY DEFAULT address
Source: Allen-Br_2b:0d:9a (00:00:bc:2b:0d:9a)
Address: Allen-Br_2b:0d:9a (00:00:bc:2b:0d:9a)
.... ...0 .... .... .... .... = Multicast: This is a UNICAST frame
.... ..0. .... .... .... .... = Locally Administrated Address: This is a FACTORY DEFAULT address
Type: IP (0x0800)
Internet Protocol, Src: 192.168.11.10 (192.168.11.10), Dst: 239.192.2.65 (239.192.2.65)
Version: 4
Header length: 20 bytes
Differentiated Services Field: 0x00 (DSCP 0x00: Default; ECN: 0x00)
0000 00.. = Differentiated Services Codepoint: Default (0x00).... ..0. = ECN-Capable Transport (ECT): 0
.... ...0 = ECN-CE: 0
Total Length: 52
Identification: 0xfb83 (64387)
Flags: 0x00
0... = Reserved bit: Not set.0.. = Don't fragment: Not set
..0. = More fragments: Not set
Fragment offset: 0
Time to live: 1
Protocol: UDP (0x11)
Header checksum: 0x0082 [correct]
Good: True
Bad : False
Source: 192.168.11.10 (192.168.11.10)
Destination: 239.192.2.65 (239.192.2.65)
User Datagram Protocol, Src Port: 2222 (2222), Dst Port: 2222 (2222)
Source port: 2222 (2222)
Destination port: 2222 (2222)
Length: 32
Checksum: 0x1b4a [correct]
EtherNet/IP (Industrial Protocol)
Item Count: 2
Type ID: Sequenced Address Item (0x8002)
Length: 8
Connection ID: 0x003a7e82
Sequence Number: 24378242
Type ID: Connected Data Item (0x00b1)
Length: 6
Data: 72242D330000