Frank, I've only checked two of the "attacking" IPs, but they are both
BigIP load balancers. I'd bet that they all are, and these packets are
some sort of probe to see if a host that contacted them before is still
alive.
Paul Schmehl ([EMAIL PROTECTED])
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu/ir/security/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html