Hi All,
in the last 2 weeks i encounter a rising number of icmp packets hitting my
firewall, which results in the following errors. the first icmp packet is
coming to qfe0, the external nic of firewall, and is accepted by a
corresponding rule. at the same time a icmp packet, with exactly same
destination and source as the previous icmp packet, is coming to hme1, the
internal nic of firewall, and gets dropped. can someone explain what is
happening. the following are the two log entries.
the firewall is Sparc based and running Solaris 9/64bit with CP NG R55.
Number: 351248
Date: 7May2004
Time: 14:23:36
Product: VPN-1 & FireWall-1
Interface: qfe0
Origin: eukey004 (10.128.11.2)
Source: L0626P05.dipool.highway.telekom.at (62.46.142.37)
Destination: ZZ__extIP_xx.xx.88.190 (xx.xx.88.190)
Protocol: icmp
Action: Accept
Type: Log
Rule: 1
Information: ICMP: Echo Request
ICMP Type: 8
ICMP Code: 0
Number: 351249
Date: 7May2004
Time: 14:23:36
Product: VPN-1 & FireWall-1
Interface: hme1
Origin: eukey004 (10.128.11.2)
Source: L0626P05.dipool.highway.telekom.at (62.46.142.37)
Destination: ZZ__extIP_xx.xx.88.190 (xx.xx.88.190)
Protocol: icmp
Action: Drop
Type: Log
Rule:
Information: ICMP: Echo Request
ICMP Type: 8
ICMP Code: 0
message_info: Address spoofing
regards
waldemar
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================