Community discussions

MikroTik App
 
wwwevecom
newbie
Topic Author
Posts: 39
Joined: Tue Feb 28, 2012 7:53 pm

420Mbps inside trafic

Wed Sep 11, 2019 5:29 pm

Hello, I see a lot of traffic 400-500 Mbps, inside traffic with src address ff02::fb:5353; and Blocks the network???
You do not have the required permissions to view the files attached to this post.
 
joegoldman
Forum Veteran
Forum Veteran
Posts: 767
Joined: Mon May 27, 2013 2:05 am

Re: 420Mbps inside trafic

Thu Sep 12, 2019 4:41 am

that is specifically the CAPsMAN tunneling protocol - not sure why so much data would be going through it if not doing rolling upgrade etc - having it on all interfaces like that makes me think a bridge or loop issue.

Perhaps see if you can capture the traffic and load it up in wireshark so you can see the content of the traffic and get an idea of what its trying to do / what might be going wrong.

Short term fix might be to disable / enable CAPsMAN manager or reboot the head-end device.
 
wwwevecom
newbie
Topic Author
Posts: 39
Joined: Tue Feb 28, 2012 7:53 pm

Re: 420Mbps inside trafic

Thu Sep 12, 2019 12:01 pm

Hello, I caught the villain. I named him 11 september hack. this is what helped me - block multicast on bridge
/interface bridge filter add chain=forward in-bridge=bridge-vlan10-wifi-mall packet-type=multicast action=drop (optionaly mac-protocol=ipv6)
/interface bridge settings set use-ip-firewall=yes
And then locate multicast source from Wi-Fi point

Who is online

Users browsing this forum: HesamEdin, johnb175a, SeparateReality and 25 guests