ICMP Queue overflow

Microsoft.Windows.RemoteAccess.Monitor.DA_DOSP_HEURISTIC_INBOUND_RATE_LIMIT_ICMPv6 (UnitMonitor)

Network Security ICMP Queue Overflow Warning.

Knowledge Base article:

Summary

Network Security ICMP Queue Overflow Warning.

Causes

The Inbound Rate Limit Discarded ICMPv6 Packets/sec counter has exceeded a defined threshold. View this counter under IPsec DOS Protection in Performance Monitor.This counter specifies the rate at which ICMPv6 packets are received on a public adapter, and discarded because they exceeded the rate limit for ICMPv6 packets per second.

Resolutions

Monitor the server for signs of a spoofing attack.

Element properties:

TargetMicrosoft.Windows.RemoteAccess.DirectAccessServer.Class
Parent MonitorSystem.Health.SecurityState
CategoryCustom
EnabledTrue
Alert GenerateTrue
Alert SeverityError
Alert PriorityNormal
Alert Auto ResolveTrue
Monitor TypeMicrosoft.Windows.RemoteAccess.Monitor.Heuristic.MonitorType
RemotableTrue
AccessibilityPublic
Alert Message
ICMP Queue Overflow

Error Description - {0}
Error Cause - {1}
Error Resolution - {2}
RunAsDefault