Snort mailing list archives
Re: Alerts of the ICMP relationship with smtp connection?
From: Frank Knobbe <frank () knobbe us>
Date: Tue, 31 May 2005 02:22:20 -0500
On Mon, 2005-05-30 at 13:40 -0700, Paulo wrote:
I didn't solve this yet. Please, anyone can help me?
Maybe you didn't get responses because it's not a Snort related issue. To answer your question, read up on Path Maximum Transmit Unit (PMTU) Discovery by googling it. Here a couple links that Google spit out right away. http://www.netheaven.com/pmtu.html which also references ftp://ftp.rfc-editor.org/in-notes/rfc1191.txt While you are learning about PTMU, please review your firewall rule set and make sure you don't block ALL inbound ICMP packets. Please let at least type 3 and type 11 ICMP packets through. (Hint: The remote mail servers are sending a large ICMP packet in order to discover the MTU between them and you. It is harmless traffic.) Hope that helps, Frank
Attachment:
signature.asc
Description: This is a digitally signed message part
Current thread:
- Alerts of the ICMP relationship with smtp connection? Paulo (May 24)
- Re: Alerts of the ICMP relationship with smtp connection? Matt Jonkman (May 24)
- <Possible follow-ups>
- Re: Alerts of the ICMP relationship with smtp connection? Paulo (May 24)
- Re: Alerts of the ICMP relationship with smtp connection? Paulo (May 30)
- Re: Alerts of the ICMP relationship with smtp connection? Frank Knobbe (May 31)
- Re: Alerts of the ICMP relationship with smtp connection? Paulo (Jun 06)
- Re: Alerts of the ICMP relationship with smtp connection? Frank Knobbe (May 31)
- RE: Alerts of the ICMP relationship with smtp connection? Paulo (Jun 07)
- RE: Alerts of the ICMP relationship with smtp connection? Briggs, Bruce (Jun 07)
- RE: Alerts of the ICMP relationship with smtp connection? Paulo (Jun 07)
- RE: Alerts of the ICMP relationship with smtp connection? Briggs, Bruce (Jun 07)
- Snort Inline again.... Xavier Cabrera (Jun 07)
- RE: Alerts of the ICMP relationship with smtp connection? Paulo (Jun 08)
- RE: Alerts of the ICMP relationship with smtp connection? Paulo (Jun 10)