Strange response from PIX

From: dissolved (dissolved_at_comcast.net)
Date: 06/30/05

  • Next message: Alexis Villagra - VILSOL LatinAmerica: "ANTIVIRUS and FIREWALL leaders?"
    To: <security-basics@securityfocus.com>
    Date: Wed, 29 Jun 2005 20:47:41 -0400
    
    

    Hi all,

    From the DMZ (1.0), I ran an nmap scan (-sA switch) towards the subnet my
    PIX protects (192.168.2.0 /24). I ran a sniffer while doing this, and
    noticed the PIX responded with an ip of 10.89.112.1 I dont have a class
    A scheme. Why is this 10.88.112.1 address showing up from the PIX?

    05:10:05.232940 IP (tos 0x0, ttl 254, id 39360, offset 0, flags [none],
    proto: ICMP (1), length: 56) 10.89.112.1 > 192.168.1.5: ICMP host
    192.168.2.1 unreachable - admin prohibited filter, length 36

    thanks


  • Next message: Alexis Villagra - VILSOL LatinAmerica: "ANTIVIRUS and FIREWALL leaders?"

    Relevant Pages

    • Re: Someone can explain this to me?
      ... > Cisco3640 core router as dgw of the network, ... > Eigrp protocol running on all the devices except the pix. ... > 3640 (remember, this is the dgw of the subnet), all seems ok. ... It sounds like the 1712 is advertising a route to 172.16.1.107 to the ...
      (comp.dcom.sys.cisco)
    • Cisco PIX SSH/telnet dDOS vulnerability CSCdy51810
      ... Cisco PIX SSH/telnet DOS vulnerability CSCdy51810 ... will answer to connection request sent to the subnet ... BindView's RAZOR team) show the free memory counter ...
      (Bugtraq)
    • Re: Client Machine cannot see Active Directory
      ... > 3.0 uses a netgear wireless router to allow wireless access for some ... > 0.0 is the subnet for our remote location. ... > by a hardware vpn between a Cisco Pix 515 and a Cisco Pix 501. ... is the client having problems accessing AD on the wireless 3.x subnet? ...
      (microsoft.public.win2000.active_directory)
    • Someone can explain this to me?
      ... Class B subnet 172.16.0.0/16 with about 500 hosts. ... Cisco Pix506 vpn gateway, address 172.16.1.107 ... Eigrp protocol running on all the devices except the pix. ...
      (comp.dcom.sys.cisco)
    • Changed Inside IP subnet on PIX 501, cant VPN to PIX 515
      ... So I have a PIX 501 that I configured to use the 10.14.0.0/16 subnet. ... Outside Interface is DHCP, ComCast Internet ... Outside interface it DHCP/PPPoE, AT&T DSL Internet ...
      (comp.dcom.sys.cisco)