I used a netflow tool to show that the server sent out a message to all of the APs at the same time and then all of the APs sent a continuous flow to each other. This caused up to 4 Mbps of traffic that crushed our sites that have 2 T1s. The source and destination ports were UDP 5555. I had to apply an acl on the routers to block these flows. The flows were ongoing from 9:13 AM until 12:45 the next morning when I applied the ACL. After I woke up, I checked again and all of the flows had stopped.
So what happened?