Flooded with ICMP Unreachable Messages
Hi,
One of my servers has recently been sending out 400-500 ICMP Unreachable messages per second.
I'm aware these messages are normally sent when a connection is attempted on a closed UDP port, but I'm trying to look into this a bit deeper.
Does anyone know how to log what port these connections are attempting to connect on? I want to make sure it's not an actual port in use (such as bind), that is denying valid connection attempts for some reason. Perhaps some tcpdump or netstat arguments?
Thanks!
|