Snort mailing list archives
ICMP destination doubt
From: Clayton Mascarenhas <masclaythesnort () yahoo com>
Date: Wed, 19 Mar 2003 10:29:32 -0800 (PST)
01/29-00:17:09.057769 [**] [1:485:2] ICMP Destination Unreachable (Communication Administratively Prohibited) [**] [Classification: Misc activity] [Priority: 3] {ICMP} 10.x.x.x -> 132.x.x.x In the alert shown above .... does it mean that 132.x.x.x was the machine that tried to send a packet to another machine 10.x.x.x .. but somewhere along the way a router filtered the 132.x.x.x ip address and thus sent an icmp packet back to 132.x.x.x.Is this correct?? Or is it the other way round... as in 10.x.x.x is the one who sent a packet... and so on.. Or is 10.x.x.x a router address (not a host address) thats sending this packet?? Please help me out. --------------------------------- Do you Yahoo!? Yahoo! Platinum - Watch CBS' NCAA March Madness, live on your desktop!
Current thread:
- ICMP destination doubt Clayton Mascarenhas (Mar 21)
- RE: ICMP destination doubt Gregory W. Ratcliff (Mar 21)