Quick question for you guys.
I have a small setup consisting of the following:
T1 --> Cisco 2600 Router --> (2) 24 Port HP Unmanaged Switches --> Workstations
I'm not sure if this is normal or not, but I'm seeing a huge amount of ARP broadcasts originating from the interface on the 2600. Basically with each broadcast saying "Who has this ip address" tell "interface on Cisco"
Each broadcast seems to be in sequential order of IP address and doesn't really seem to stop at all.
Is there a configuration issue, or is all of this still backwash from the blaster/welchia worm? I know for a fact that none of my workstations/servers are infected (I was patched before the whole mess began), but are these other infected internet machines that are arping for my machines?
Thanks for the info in advance.
I have a small setup consisting of the following:
T1 --> Cisco 2600 Router --> (2) 24 Port HP Unmanaged Switches --> Workstations
I'm not sure if this is normal or not, but I'm seeing a huge amount of ARP broadcasts originating from the interface on the 2600. Basically with each broadcast saying "Who has this ip address" tell "interface on Cisco"
Each broadcast seems to be in sequential order of IP address and doesn't really seem to stop at all.
Is there a configuration issue, or is all of this still backwash from the blaster/welchia worm? I know for a fact that none of my workstations/servers are infected (I was patched before the whole mess began), but are these other infected internet machines that are arping for my machines?
Thanks for the info in advance.