Support Questions

Find answers, ask questions, and share your expertise

Suspecious UDP traffic related to UDP 7191 CDP Agent Flood

avatar
Explorer

Hello,

 

After CDP deployment we observed a suspecious traffic from diffrent internet IPs to CDP Agent

port UDP 7191

After an investigation it comes from 

/opt/cloudera/cm-agent/bin/flood

Please could anyone give us more details about this traffic ?

UDP 7191 suspecious traffic.PNG

 

Regards

Yasine L

5 REPLIES 5

avatar

A quick dig shows this port 7191 is for parcel distribution and internal only

Peer-to-peer parcel distribution7190, 7191Hosts > All Hosts > Configuration > P2P Parcel Distribution PortUsed to distribute parcels to cluster hosts during installation and upgrade operations.

Reference

https://docs.cloudera.com/cdp-private-cloud-base/7.1.6/installation/topics/cdpdc-ports-used-by-cm.ht...

 

 

avatar
Explorer

So normally it should be an internal traffic, but the firewall is showing external traffic to different IPs in different countries.

 

 

 

avatar
Community Manager

@Yasine, Has the reply helped resolve your issue? If so, please mark the appropriate reply as the solution, as it will make it easier for others to find the answer in the future. 



Regards,

Vidya Sargur,
Community Manager


Was your question answered? Make sure to mark the answer as the accepted solution.
If you find a reply useful, say thanks by clicking on the thumbs up button.
Learn more about the Cloudera Community:

avatar
Master Collaborator

Hello @Yasine Thank you for bringing this in our Community.


So normally it should be an internal traffic, but the firewall is showing external traffic to different IPs in different countries.

May I ask you to be specific and present evidences such as screenshots, tests or logs citing this issue? 

Thanks

V

avatar
Contributor

@vaishaakb 

I noticed this same activity after deploying to the latest version of CM and after deploying parcels in my Lab cluster.  I started getting P2P violations from my IDS and IPS. Is there any way to control the external p2p process? 

I've gone ahead and attached screen captures from my firewall. 

CDP - 7.1.9-1.cdh7.1.9.p0.44702451 - CM - 7.11.3

Example of the detection:

Screenshot 2023-10-13 at 10.12.57 PM.png

All 5 of my nodes repeatedly trying to talk across the globe. 

Screenshot 2023-10-13 at 10.12.37 PM.png