Snort mailing list archives

ICMP destination doubt


From: Clayton Mascarenhas <masclaythesnort () yahoo com>
Date: Wed, 19 Mar 2003 10:29:32 -0800 (PST)


 

01/29-00:17:09.057769 [**] [1:485:2] ICMP Destination Unreachable (Communication Administratively Prohibited) [**] 
[Classification: Misc activity] [Priority: 3] {ICMP} 10.x.x.x -> 132.x.x.x

In the alert shown above .... does it mean that 132.x.x.x was the machine that tried to send a packet to another 
machine 10.x.x.x .. but somewhere along the way a router filtered the 132.x.x.x ip address and thus sent an icmp packet 
back to 132.x.x.x.Is this correct?? 

Or is it the other way round... as in 10.x.x.x is the one who sent a packet... and so on..

Or is 10.x.x.x a router address (not a host address) thats sending this packet??

Please help me out.

 



---------------------------------
Do you Yahoo!?
Yahoo! Platinum - Watch CBS' NCAA March Madness, live on your desktop!

Current thread: