Hi, Two networks from the APNIC-Range send every day icmp-messages type 11 code 0 (time to live exceeded in transit) to our whole public networks. proto src dst icmp-type icmp-code icmp 254.c243.ethome.net.tw 192.168.1.0 11 0 icmp 61.132.74.1 192.168.1.0 11 0 (the dst-ipadress is only an example) As i know a icmp-message from this type can`t use for mapping a networkstructure, because there isn`t send back a generated reply-packet from the target host. For which reason more send someone this type of packets to our networks?? any hints? best regards Thomas - [To unsubscribe, send mail to [EMAIL PROTECTED] with "unsubscribe firewalls" in the body of the message.]
