LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-06-2005, 03:03 PM   #1
hacinn
LQ Newbie
 
Registered: Jun 2004
Posts: 11

Rep: Reputation: 0
Question Snort alerts of the ICMP relationship with smtp connection?


Hi,

I am using Snort version Version 2.3.2 (Build 12).
I have in my snort logs the alerts:

366 - ICMP Ping *nix
384 - ICMP Ping
368 - Ping BSDtype

I investigated my others systems logs and in the time
that this alert is recorded is the same that
registered smtp connection in the maillog arquive from
my postfix server.

The source IP address in snort's log is equal the
destination IP address in the maillog to smtp
connection.

My smtp server is a Postfix version 1.1.3.

This alerts can to be generated by destination mail server when
it receives mails?

Any friends have said about the path MTU discovery, it's true? How can
i to confirm this?

This alerts is a false positive?

Thanks by help
 
Old 06-21-2005, 07:10 AM   #2
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Mail servers can generate icmp messages, eg when busy, or packets are received out of order.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
snort alerts lord-fu Linux - Security 1 11-25-2005 03:28 PM
Snort Alerts ?? zahra79 Linux - Networking 5 06-22-2005 05:11 AM
Suggestions for best way to get snort alerts zuessh Linux - Security 9 08-29-2004 09:40 PM
Snort only alerts snmp gummimann Linux - Security 5 02-04-2004 01:03 PM
Snort Alerts knight_ridda Linux - Security 13 06-21-2003 04:32 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 03:22 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration