Hi to all of you,
I'm experiencing some trouble with my UTM since the last past days.
Does anybody know what's going on here?
My mailbox is stuck with a few thousand emails with this message.
Weird is that I didn't change anything, so please be so kind and supply a hint for me! :-)
Cheers,
Michael
I'm experiencing some trouble with my UTM since the last past days.
Does anybody know what's going on here?
My mailbox is stuck with a few thousand emails with this message.
Weird is that I didn't change anything, so please be so kind and supply a hint for me! :-)
Code:
Intrusion Prevention Alert
An intrusion has been detected. The packet has *not* been dropped.
If you want to block packets like this one in the future,
set the corresponding intrusion protection rule to "drop" in WebAdmin.
Be careful not to block legitimate traffic caused by false alerts though.
Details about the intrusion alert:
Message........: PROTOCOL-ICMP PING BSDtype
Details........: http://www.snort.org/search/sid/368?r=1
Time...........: 2012-12-03 20:22:18
Packet dropped.: no
Priority.......: low
Classification.: Misc activity
IP protocol....: 1 (ICMP)
Source IP address: 109.230.243.166 (frankfurt01.worker.wemonit.de)
- http://www.dnsstuff.com/tools/ptr.ch?ip=109.230.243.166
- http://www.ripe.net/perl/whois?query=109.230.243.166
- http://ws.arin.net/cgi-bin/whois.pl?queryinput=109.230.243.166
- http://cgi.apnic.net/apnic-bin/whois.pl?search=109.230.243.166
Source port: 0
Destination IP address: 11.22.33.44 (www.mydomain.de)
- http://www.dnsstuff.com/tools/ptr.ch?ip=11.22.33.44
- http://www.ripe.net/perl/whois?query=11.22.33.44
- http://ws.arin.net/cgi-bin/whois.pl?queryinput=11.22.33.44
- http://cgi.apnic.net/apnic-bin/whois.pl?search=11.22.33.44
Destination port: 0
-- System Uptime : 1 day 22 hours 20 minutes System Load : 0.28 System Version : Sophos UTM 9.004033 Please refer to the manual for detailed instructions.
Cheers,
Michael