We currently have a very large outbound DDOS Attack coming from one of our machines which is on a Brocade switch and monitored by PRTG. I am looking at the sFlow v5 8 sensor and see Top Talkers and Top Connections, but cannot make heads or tails of these live circle graphs. Can anyone please shed some light on how I can figure out what IP this traffic is originating from?
Thank you!
You didn't mention which
Brocade
switch this was but I suspect it's one of theirFastIron/ICX
family so here is how to "shut off" or disable a port on aBrocade FastIron
orICX switch
.To disable port 8 of a Brocade device, enter the following.
I got it from the following if you want to see more:
If you have a different
Brocade
switch, reply back with the details and I'll reply again.