Quantcast
Channel: Sophos User Bulletin Board
Viewing all articles
Browse latest Browse all 14361

Possible bug in IPS rules - 1 PROTOCOL-ICMP Destination Unreachable Fragmentation N

$
0
0
I'm getting hundreds of thousands of these errors per day.
It looks like an error in the UTM9 protocol stack but I'm not entirely sure.

I found a thread from 2005 indicating this was a bug back then. It now appears to be a regression.

The source of the traffic is a bittorrent stream which provides the big numbers.

Thoughts?

Thanks.

Details:
These started as soon as I upgraded to UTM9.
1 source: my Astaro UTM9
1 destination: bittorrent client machine
Snort Error:
1
PROTOCOL-ICMP Destination Unreachable Fragmentation Needed and DF bit was set
113,442
100.00%

Viewing all articles
Browse latest Browse all 14361

Trending Articles