On Mon, Jul 08, 2002 at 10:36:56AM -0400, Ramin Alidousti wrote: > On Mon, Jul 08, 2002 at 04:29:51PM +0200, Raymond Leach wrote: > > > On Mon, 2002-07-08 at 16:07, Ed Street wrote: > > > Hello, > > > > > > > > > Looks like station 10.0.0.19 on eth2 tried to ping 199.181.167.201 and > > > it was droped. > > > > > I've checked the process list on 10.0.0.19 and also restarted it just to > > make sure, and there is nothing that is trying to ping anywhere. > > > > Isn't ICMP CODE 0 TYPE 0 a reply? Doesn't this log entry represent > > 10.0.0.19's reply to an echo request? > > Don't you have any backdoor?? If not, then 10.0.0.19 might be replying > to a spoofed ping from the inside...
Second thought. It probably isn't due to a backdoor as this backdoor would need to do the same natting that you're doing on your firewall. So it'd narrow down to the spoofed ping from the inside. Ramin
