i am getting a lot of these on my seattle internet exchange interface May 4 00:18:39 rpd[1485]: rv_listen_accept: Connection attempt from unconfigured session: ::Ffff:222.77.14.229+40604 May 4 00:23:36 rpd[1485]: rv_listen_accept: Connection attempt from unconfigured session: ::ffff:222.77.14.229+20885 May 4 00:23:38 rpd[1485]: rv_listen_accept: Connection attempt from unconfigured session: ::ffff:222.77.14.229+38407 May 4 00:28:35 rpd[1485]: rv_listen_accept: Connection attempt from unconfigured session: ::ffff:222.77.14.229+47648 May 4 00:28:37 rpd[1485]: rv_listen_accept: Connection attempt from unconfigured session: ::ffff:222.77.14.229+43036 May 4 00:33:35 rpd[1485]: rv_listen_accept: Connection attempt from unconfigured session: ::ffff:222.77.14.229+11306 May 4 00:33:37 rpd[1485]: rv_listen_accept: Connection attempt from unconfigured session: ::ffff:222.77.14.229+21558
that looks like a mapped ipv4 address, except that 222.77.14.229 is chinanet fujian address and chinanet is not at the six as far as i can tell i wanna do a tcpdump to find the MAC of the other party. but i can not make sense of ::ffff:222.77.14.229 so i can put it in a tcpdump expression tcpdump -n -i fe-0/3/2.0 -XX port 179 host ????? any clues? randy _______________________________________________ juniper-nsp mailing list juniper-nsp@puck.nether.net https://puck.nether.net/mailman/listinfo/juniper-nsp