Strange LOG message from iptables. Any ideas?
Hi,
I've set up iptables including some logging. I found logs similar to the one below.
Feb 2 22:59:32 deb kernel: IPT_IN_DROP_ICMP_WLAN0 IN=wlan0 OUT= MAC=00:14:a5:e8:56:a0:00:14:7f:1f:1c:b4:08:00 SRC=87.131.231.80 DST=192.168.165.77 LEN=98 TOS=0x00 PREC=0x00 TTL=244 ID=51624 PROTO=ICMP TYPE=3 CODE=1 [SRC=192.168.165.77 DST=87.131.231.80 LEN=70 TOS=0x00 PREC=0x00 TTL=52 ID=0 DF PROTO=UDP SPT=17236 DPT=16809 LEN=50 ]
As you can see, the IP 87.X.X.X is sending me an ICMP type 3 packet. It then gives me a [] with PROTO=UDP. Is this ICMP tunneling or what? I should note that I am running some P2P applications. Thanks for your help.
Last edited by LinuxGeek; 02-02-2007 at 03:08 PM.
|