Community discussions

MikroTik App
 
Faceless
just joined
Topic Author
Posts: 18
Joined: Sat Mar 03, 2018 4:03 pm
Location: Ukraine
Contact:

Mikrotik Neighbor aka CDP/VTP/.. Dos

Thu Apr 26, 2018 7:16 pm

Multicast ot DST.MAC 01:00:0C:CC:CC:CC causing RAM consumtion.So even using
1) chain=input action=drop in-bridge=bridge1 dst-mac-address=01:00:0C:CC:CC:CC/FF:FF:FF:FF:FF:FF packet-type=multicast limit=1,5 log=no log-prefix=""
2) chain=input action=drop in-bridge=bridge1 dst-mac-address=01:00:0C:CC:CC:CC/FF:FF:FF:FF:FF:FF limit=1,2 log=no log-prefix="
We can drop these packets but ip neighbor table overflows using more RAM.Also then we can't disable port on trigger or clean neighbor list.
On cisco maybe it can be done when flooding cdp packets