Michael McClure wrote:
> 
> In the meantime, I have *a bunch* of this:
> 
> Jul  7 03:04:00 mikerouter kernel: Packet log: input DENY eth0 PROTO=1
> 0.0.0.0:3 80.135.217.223:3 L=56 S=0x00 I=42918 F=0x0000 T=150 (#17)
> Jul  7 03:04:00 mikerouter kernel: Packet log: input DENY eth0 PROTO=1
> 0.0.0.0:3 80.14.16.161:3 L=56 S=0x00 I=62745 F=0x0000 T=150 (#17)
> Jul  7 03:04:00 mikerouter kernel: Packet log: input DENY eth0 PROTO=1
> 0.0.0.0:3 80.136.236.230:3 L=56 S=0x00 I=61390 F=0x0000 T=150 (#17)
> Jul  7 03:04:01 mikerouter kernel: Packet log: input DENY eth0 PROTO=1
> 0.0.0.0:3 211.243.227.2:3 L=56 S=0x00 I=25947 F=0x0000 T=150 (#17)
> 
> They are coming from everywhere -- should I be concerned?  What is this?

www.iana.org is your friend ;>

Well, according to <http://www.iana.org/assignments/protocol-numbers>,
protocol 1 is icmp.

Here: <http://www.iana.org/assignments/icmp-parameters> we see that icmp
type 3 is ``Destination Unreachable ... [RFC792]''.

Which firewall are you using?

When you say, ``They are coming from everywhere ...'', what do you
mean?  The source in all that you've posted is 0.0.0.0, whereas the
destination varies.

Tell us what is your ip address/network numbers, and we may better
analyze your situation.

What do you think?

-- 

Best Regards,

mds
mds resource
888.250.3987

Dare to fix things before they break . . .

Our capacity for understanding is inversely proportional to how much we
think we know.  The more I know, the more I know I don't know . . .


-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
We have stuff for geeks like you.
http://thinkgeek.com/sf
------------------------------------------------------------------------
leaf-user mailing list: [EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/leaf-user
SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html

Reply via email to