Virus Throttling (5300xl Switches Only)
Connection-Rate Log and Trap Messages
Connection-Rate Log and Trap Messages
These messages appear in the switch’s Event Log. If SNMP trap receivers are
configured on the switch, it also sends the messages to the designated
receiver(s).
Message Meaning
Address not found in list of blocked Appears in the CLI when the vlan < vid > connection-
hosts.
rate-filter unblock
command has been executed to
unblock hosts that are not currently blocked.
W < mm/dd/yy hh:mm:ss > virusfilt: Source IP A warning that results when a port configured for notify-
address
< xxx.xxx.xxx.xxx > is exhibiting
only detects a relatively high number of connection-rate
virus-like behavior
attempts from a host.
W < mm/dd/yy hh:mm:ss > virusfilt: Source IP A warning and indication of the switch’s response when a
address
< xxx.xxx.xxx.xxx > has been throttled
port configured for throttle detects a relatively high
number of connection-rate attempts from a host.
W < mm/dd/yy hh:mm:ss > virusfilt: Src IP A warning and indication of the switch’s response when a
< xxx.xxx.xxx.xxx > blocked
port configured for block detects a relatively high number
of connection-rate attempts from a host.
3-31