Quantcast
Channel: Sophos User Bulletin Board
Viewing all articles
Browse latest Browse all 14361

IPS / PING BSDtype

$
0
0
Hi to all of you,

I'm experiencing some trouble with my UTM since the last past days.
Does anybody know what's going on here?
My mailbox is stuck with a few thousand emails with this message.

Weird is that I didn't change anything, so please be so kind and supply a hint for me! :-)


Code:

Intrusion Prevention Alert

An intrusion has been detected. The packet has *not* been dropped.
If you want to block packets like this one in the future,
set the corresponding intrusion protection rule to "drop" in WebAdmin.
Be careful not to block legitimate traffic caused by false alerts though.

Details about the intrusion alert:

Message........: PROTOCOL-ICMP PING BSDtype
Details........: http://www.snort.org/search/sid/368?r=1
Time...........: 2012-12-03 20:22:18
Packet dropped.: no
Priority.......: low
Classification.: Misc activity
IP protocol....: 1 (ICMP)

Source IP address: 109.230.243.166 (frankfurt01.worker.wemonit.de)
- http://www.dnsstuff.com/tools/ptr.ch?ip=109.230.243.166
- http://www.ripe.net/perl/whois?query=109.230.243.166
- http://ws.arin.net/cgi-bin/whois.pl?queryinput=109.230.243.166
- http://cgi.apnic.net/apnic-bin/whois.pl?search=109.230.243.166
Source port: 0
Destination IP address: 11.22.33.44 (www.mydomain.de)
- http://www.dnsstuff.com/tools/ptr.ch?ip=11.22.33.44
- http://www.ripe.net/perl/whois?query=11.22.33.44
- http://ws.arin.net/cgi-bin/whois.pl?queryinput=11.22.33.44
- http://cgi.apnic.net/apnic-bin/whois.pl?search=11.22.33.44
Destination port: 0
       
-- System Uptime : 1 day 22 hours 20 minutes System Load : 0.28 System Version : Sophos UTM 9.004033 Please refer to the manual for detailed instructions.


Cheers,
Michael

Viewing all articles
Browse latest Browse all 14361

Trending Articles