Re: Interesting fw log: "ICMP type 3 not embeddable"

From: Michael Heiming (
Date: 06/16/02

From: Michael Heiming <>
Date: Sun, 16 Jun 2002 13:00:14 +0200

RainbowHat (<>):

> < Michael Heiming
>>Jun 15 00:38:16 host kernel: invalid IN=ppp0 OUT= MAC=
>>SRC= DST=My.external.IP
>>LEN=56 TOS=0x00 PREC=0x00 TTL=56 ID=30304 PROTO=ICMP TYPE=3 CODE=3
> RFC760: Type 3 = destination unreachable, Code 3 = port
> unreachable
> (DTAG-DIAL14) Deutsche Telekom AG

Yes, observed this, probably a dialup/DSL connection, however
logging stopped about 10h after it started. Long before I changed
my firewall, concerning invalid packets (added the --reject-with),
due to Ian's advice.

$IPTABLES -A invalid -j REJECT -j LOG --log-prefix "INVALID "
--reject-with icmp-port-unreachable

So I'm not sure if this really was the reason, I'll keep an eye on

> Someone send source IP spoofed TCP or UDP packet to
> your box. Your box did not log this incoming packet and REJECT the
> packet. The REJECT-ed ICMP 3 3 embedded TCP or UDP packet went to
> upper stream router of The router was
> mis-implemented|configured and responded ICMP 3 embedded ICMP 3
> packet to your box. Your box logged this malformed packet and you
> observed it.

That what I initially thought about the event too. Thx for
answering, looks like there're some more things to learn about

Michael Heiming

Remove the +SIGNS case mail bounces.