Re: eigrp bounce...suspect nimda virus

From: Dan.Thorson@xxxxxxxxxxx
Date: Mon Jun 10 2002 - 10:19:24 GMT-3


   
> What debug/show commands (if any) can we use on router to identify what
source IP (host) has the Nimda virus.

Turn on flow switching (interface command "ip route-cache flow"), and then
do a "show ip cache flow". Look for a single source IP which is scanning
IP blocks (it will often show up with a destination of "null" -- so "show
ip cache flow | inc Null").

danT

========================================
Dan Thorson - Seagate Technology, LLC
desk +1 (952) 402-8293 fax +1 (952) 402-1007
SeaTel 8-402-8293
========================================



This archive was generated by hypermail 2.1.4 : Tue Jul 02 2002 - 08:12:30 GMT-3