RE: What could this icmp mean?

From: Andrew Shore (andrew.shore_at_holistecs.com)
Date: 02/24/05

  • Next message: dissolved: "RE: encrypted data honeypots and IDS"
    Date: Thu, 24 Feb 2005 22:51:58 -0000
    To: "Tomas" <s.tomas@gmail.com>, <security-basics@securityfocus.com>
    
    

    These are ICMP redirect packets.

    Your default route is not the best to the desired network so the router
    is telling the client to use a different router.

    Its to reduce the traffic on the network.

    HTH

    -----Original Message-----
    From: Tomas [mailto:s.tomas@gmail.com]
    Sent: 22 February 2005 13:11
    To: security-basics@securityfocus.com
    Subject: What could this icmp mean?

    Hello list,

    We have networks (10.30.0.0/24 and 10.30.1.0/24) connected trough VPN
    and
    one internet line. The gateways for VPN are 10.30.0.1 from one side and
    10.30.1.1 from the other, and 10.30.1.254 for internet (for both
    networks).

    I've launched tcpdump today on my internet firewall's internal interface
    (10.30.1.254) and I found this:

    10.30.1.254 > 10.30.1.16: icmp: redirect 10.30.0.4 to host 10.30.1.1 for
    10.30.1.16.445 > 10.30.0.4.1959: [|tcp] (DF) (ttl 127, id 7691, bad
    cksum
    c76d! differs by 100) (ttl 255, id 23807)

    I'm a bit confused, what could this icmp mean? First of all, I'm sure
    that
    neither of these hosts (10.30.1.254, 10.30.1.16, 10.30.0.4) are sending
    any
    icmp requests (I'm not sure about 10.30.1.1; it's not in my control).
    And
    the second of all, why the checksum is bad?


  • Next message: dissolved: "RE: encrypted data honeypots and IDS"

    Relevant Pages

    • Re: Unable to obtain a server- assigned IP address Try again later or enter an IP address in Net
      ... I can go to Control Panel - Network and Internet Connections - ... If yours is not a subset of your router, ... I have a LINKSYS router (4 port connection) - I have my cable modem ...
      (microsoft.public.pocketpc)
    • Re: Boot-up question on SBS2K3
      ... > The router separates you from the Internet. ... > network. ... >>>> 2 Nics, broadband cable modem connected into the external NIC, ...
      (microsoft.public.windows.server.sbs)
    • Re: Open access point for clients
      ... Boss wants clients to have access to internet ... If you knew enough to get the network setup like it is already then you ought to know how to do this. ... If you can't get a second ip then connect one router to your isp and then connect wan ports of two additional routers to lan side of ISP connected router. ...
      (alt.internet.wireless)
    • RE: Small network with lots of features, questions
      ... Your network sounds overly complicated to me. ... to get to the internet. ... To do that, without using your server as a router, you need ...
      (microsoft.public.windows.server.networking)
    • Re: Need help closing security holes in my Windows XP home system!
      ... >>new portals of access to internet hackers, ... My router came with a default MAC address printed on the bottom. ... > your unique hardware as in your segment of the network - no other device ... > Apply ALL MS Office Updates ...
      (comp.security.firewalls)