<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Suspecious UDP traffic related to UDP 7191 CDP Agent Flood in Support Questions</title>
    <link>https://community.cloudera.com/t5/Support-Questions/Suspecious-UDP-traffic-related-to-UDP-7191-CDP-Agent-Flood/m-p/375210#M242344</link>
    <description>&lt;P&gt;So normally it should be an internal traffic, but the firewall is showing external traffic to different IPs in different countries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Aug 2023 12:41:17 GMT</pubDate>
    <dc:creator>Yasine</dc:creator>
    <dc:date>2023-08-15T12:41:17Z</dc:date>
    <item>
      <title>Suspecious UDP traffic related to UDP 7191 CDP Agent Flood</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Suspecious-UDP-traffic-related-to-UDP-7191-CDP-Agent-Flood/m-p/375206#M242340</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After CDP deployment we observed a suspecious traffic from diffrent internet IPs to CDP Agent&lt;/P&gt;&lt;P&gt;port UDP 7191&lt;/P&gt;&lt;P&gt;After an investigation it comes from&amp;nbsp;&lt;/P&gt;&lt;P&gt;/opt/cloudera/cm-agent/bin/flood&lt;/P&gt;&lt;P&gt;Please could anyone give us more details about this traffic ?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UDP 7191 suspecious traffic.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/38240i7FEF27179AED1817/image-size/large?v=v2&amp;amp;px=999" role="button" title="UDP 7191 suspecious traffic.PNG" alt="UDP 7191 suspecious traffic.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Yasine L&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 11:48:47 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Suspecious-UDP-traffic-related-to-UDP-7191-CDP-Agent-Flood/m-p/375206#M242340</guid>
      <dc:creator>Yasine</dc:creator>
      <dc:date>2023-08-15T11:48:47Z</dc:date>
    </item>
    <item>
      <title>Re: Suspecious UDP traffic related to UDP 7191 CDP Agent Flood</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Suspecious-UDP-traffic-related-to-UDP-7191-CDP-Agent-Flood/m-p/375207#M242341</link>
      <description>&lt;P&gt;A quick dig shows this port 7191 is for parcel distribution and internal only&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Peer-to-peer parcel distribution&lt;/TD&gt;&lt;TD&gt;7190, 7191&lt;/TD&gt;&lt;TD&gt;&lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;Hosts&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;All Hosts&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Configuration&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;P2P Parcel Distribution Port&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;Used to distribute parcels to cluster hosts during installation and upgrade operations.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;Reference&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.cloudera.com/cdp-private-cloud-base/7.1.6/installation/topics/cdpdc-ports-used-by-cm.html" target="_blank" rel="noopener"&gt;https://docs.cloudera.com/cdp-private-cloud-base/7.1.6/installation/topics/cdpdc-ports-used-by-cm.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 11:54:49 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Suspecious-UDP-traffic-related-to-UDP-7191-CDP-Agent-Flood/m-p/375207#M242341</guid>
      <dc:creator>steven-matison</dc:creator>
      <dc:date>2023-08-15T11:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Suspecious UDP traffic related to UDP 7191 CDP Agent Flood</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Suspecious-UDP-traffic-related-to-UDP-7191-CDP-Agent-Flood/m-p/375210#M242344</link>
      <description>&lt;P&gt;So normally it should be an internal traffic, but the firewall is showing external traffic to different IPs in different countries.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2023 12:41:17 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Suspecious-UDP-traffic-related-to-UDP-7191-CDP-Agent-Flood/m-p/375210#M242344</guid>
      <dc:creator>Yasine</dc:creator>
      <dc:date>2023-08-15T12:41:17Z</dc:date>
    </item>
    <item>
      <title>Re: Suspecious UDP traffic related to UDP 7191 CDP Agent Flood</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Suspecious-UDP-traffic-related-to-UDP-7191-CDP-Agent-Flood/m-p/375787#M242657</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/106517"&gt;@Yasine&lt;/a&gt;,&amp;nbsp;Has the reply helped resolve your issue? If so, please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Aug 2023 13:00:34 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Suspecious-UDP-traffic-related-to-UDP-7191-CDP-Agent-Flood/m-p/375787#M242657</guid>
      <dc:creator>VidyaSargur</dc:creator>
      <dc:date>2023-08-30T13:00:34Z</dc:date>
    </item>
    <item>
      <title>Re: Suspecious UDP traffic related to UDP 7191 CDP Agent Flood</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Suspecious-UDP-traffic-related-to-UDP-7191-CDP-Agent-Flood/m-p/376025#M242740</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/106517"&gt;@Yasine&lt;/a&gt;&amp;nbsp;Thank you for bringing this in our Community.&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P class="1693947253054"&gt;&lt;SPAN&gt;So normally it should be an internal traffic, but the firewall is showing external traffic to different IPs in different countries.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;May I ask you to be specific and present evidences such as screenshots, tests or logs citing this issue?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;V&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 20:57:35 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Suspecious-UDP-traffic-related-to-UDP-7191-CDP-Agent-Flood/m-p/376025#M242740</guid>
      <dc:creator>vaishaakb</dc:creator>
      <dc:date>2023-09-05T20:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: Suspecious UDP traffic related to UDP 7191 CDP Agent Flood</title>
      <link>https://community.cloudera.com/t5/Support-Questions/Suspecious-UDP-traffic-related-to-UDP-7191-CDP-Agent-Flood/m-p/377639#M243310</link>
      <description>&lt;P&gt;&lt;a href="https://community.cloudera.com/t5/user/viewprofilepage/user-id/29989"&gt;@vaishaakb&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I noticed this same activity after deploying to the latest version of CM and after deploying parcels in my Lab cluster.&amp;nbsp; I started getting P2P violations from my IDS and IPS. Is there any way to control the external p2p process?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've gone ahead and attached screen captures from my firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;CDP -&amp;nbsp;&lt;SPAN&gt;7.1.9-1.cdh7.1.9.p0.44702451 - CM - 7.11.3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Example of the detection:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-13 at 10.12.57 PM.png" style="width: 558px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/38656i4BB89668FBA3867E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-10-13 at 10.12.57 PM.png" alt="Screenshot 2023-10-13 at 10.12.57 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;All 5 of my nodes repeatedly trying to talk across the globe.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-10-13 at 10.12.37 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/38655i2F48CF14E13B8ED5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-10-13 at 10.12.37 PM.png" alt="Screenshot 2023-10-13 at 10.12.37 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 14 Oct 2023 02:31:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Support-Questions/Suspecious-UDP-traffic-related-to-UDP-7191-CDP-Agent-Flood/m-p/377639#M243310</guid>
      <dc:creator>ssummers</dc:creator>
      <dc:date>2023-10-14T02:31:19Z</dc:date>
    </item>
  </channel>
</rss>

