<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unsolicited Echo Reply in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978423#M575573</link>
    <description>I keep receiving the following alerts on my Procurve Switches "ip: icmp: Unsolicited Echo Reply from"  and the address its from is a local addresses on my net.  Sometimes a pc's address, sometimes a RF scanner or whatnot.    &lt;BR /&gt;&lt;BR /&gt;Any idea what causes this, how to stop it, or is it something I should consern myself with?  I probably get about 5 of these per day across all my switches.&lt;BR /&gt;&lt;BR /&gt;Thanks for any info.&lt;BR /&gt;Ron Bombard, Network Admin.&lt;BR /&gt;Native Textiles Inc.&lt;BR /&gt;</description>
    <pubDate>Wed, 21 May 2003 12:00:50 GMT</pubDate>
    <dc:creator>Ron Bombard</dc:creator>
    <dc:date>2003-05-21T12:00:50Z</dc:date>
    <item>
      <title>Unsolicited Echo Reply</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978423#M575573</link>
      <description>I keep receiving the following alerts on my Procurve Switches "ip: icmp: Unsolicited Echo Reply from"  and the address its from is a local addresses on my net.  Sometimes a pc's address, sometimes a RF scanner or whatnot.    &lt;BR /&gt;&lt;BR /&gt;Any idea what causes this, how to stop it, or is it something I should consern myself with?  I probably get about 5 of these per day across all my switches.&lt;BR /&gt;&lt;BR /&gt;Thanks for any info.&lt;BR /&gt;Ron Bombard, Network Admin.&lt;BR /&gt;Native Textiles Inc.&lt;BR /&gt;</description>
      <pubDate>Wed, 21 May 2003 12:00:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978423#M575573</guid>
      <dc:creator>Ron Bombard</dc:creator>
      <dc:date>2003-05-21T12:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unsolicited Echo Reply</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978424#M575574</link>
      <description>Hi&lt;BR /&gt;This may help:-&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B2355-90131/B2355-90131_top.html&amp;amp;con=/hpux/onlinedocs/B2355-90131/00/00/38-con.html&amp;amp;toc=/hpux/onlinedocs/B2355-90131/00/00/38-toc.html&amp;amp;searchterms=echo%7cUnsolicited&amp;amp;queryid=19030521-070836" target="_blank"&gt;http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B2355-90131/B2355-90131_top.html&amp;amp;con=/hpux/onlinedocs/B2355-90131/00/00/38-con.html&amp;amp;toc=/hpux/onlinedocs/B2355-90131/00/00/38-toc.html&amp;amp;searchterms=echo%7cUnsolicited&amp;amp;queryid=19030521-070836&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Also is there one router that all of these devices go through? If so check it out.&lt;BR /&gt;&lt;BR /&gt;Paula</description>
      <pubDate>Wed, 21 May 2003 12:13:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978424#M575574</guid>
      <dc:creator>Paula J Frazer-Campbell</dc:creator>
      <dc:date>2003-05-21T12:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Unsolicited Echo Reply</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978425#M575575</link>
      <description>I'd do a little investigating:  &lt;BR /&gt;&lt;BR /&gt;See:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.sans.org/resources/idfaq/traffic.php" target="_blank"&gt;http://www.sans.org/resources/idfaq/traffic.php&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Also check out the TFN exploit discussed at:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.sans.org/resources/idfaq/icmp_misuse.php" target="_blank"&gt;http://www.sans.org/resources/idfaq/icmp_misuse.php&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Ron&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 21 May 2003 12:36:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978425#M575575</guid>
      <dc:creator>Ron Kinner</dc:creator>
      <dc:date>2003-05-21T12:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unsolicited Echo Reply</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978426#M575576</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;ip: &lt;VLAN&gt;: icmp: Unsolicited Echo Reply from &lt;IP address=""&gt;&lt;BR /&gt;An unsolicited ICMP reply to a ping was received from &lt;IP address=""&gt; that was not sent by the local switch.&lt;BR /&gt;&lt;BR /&gt;The "not sent by the local switch" may help you.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Paula&lt;BR /&gt;&lt;/IP&gt;&lt;/IP&gt;&lt;/VLAN&gt;</description>
      <pubDate>Wed, 21 May 2003 12:52:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978426#M575576</guid>
      <dc:creator>Paula J Frazer-Campbell</dc:creator>
      <dc:date>2003-05-21T12:52:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unsolicited Echo Reply</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978427#M575577</link>
      <description>Also check out:-&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.iss.net/security_center/advice/Intrusions/2000109/default.htm" target="_blank"&gt;http://www.iss.net/security_center/advice/Intrusions/2000109/default.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Paula</description>
      <pubDate>Wed, 21 May 2003 12:54:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978427#M575577</guid>
      <dc:creator>Paula J Frazer-Campbell</dc:creator>
      <dc:date>2003-05-21T12:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: Unsolicited Echo Reply</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978428#M575578</link>
      <description>Also check out:-&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.iss.net/security_center/advice/Intrusions/2000109/default.htm" target="_blank"&gt;http://www.iss.net/security_center/advice/Intrusions/2000109/default.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;and &lt;BR /&gt;&lt;BR /&gt;Unsolicited echo-replies can be a sign of a Smurf ( &lt;A href="http://www.cert.org/advisories/CA-1998-01.html)amplification" target="_blank"&gt;http://www.cert.org/advisories/CA-1998-01.html)amplification&lt;/A&gt; attack.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Paula</description>
      <pubDate>Wed, 21 May 2003 12:56:18 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978428#M575578</guid>
      <dc:creator>Paula J Frazer-Campbell</dc:creator>
      <dc:date>2003-05-21T12:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: Unsolicited Echo Reply</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978429#M575579</link>
      <description>Ron&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Please assign points to your previous questions if the answers have assisted you:-&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/cm/TopSolutions/1,,CA302314!1!questions,00.html" target="_blank"&gt;http://forums.itrc.hp.com/cm/TopSolutions/1,,CA302314!1!questions,00.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;;^)&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Paula</description>
      <pubDate>Wed, 21 May 2003 13:00:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978429#M575579</guid>
      <dc:creator>Paula J Frazer-Campbell</dc:creator>
      <dc:date>2003-05-21T13:00:07Z</dc:date>
    </item>
    <item>
      <title>Re: Unsolicited Echo Reply</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978430#M575580</link>
      <description>So... it would be your guess that this is some sort of "intrusion" of some kind?   If that were the case, wouldn't I see more of these alerts, besides just the few per day?&lt;BR /&gt;&lt;BR /&gt;My firewalls allow ICMP stuff, but limit them to 1 per 60 secs.&lt;BR /&gt;&lt;BR /&gt;Is it recommended to disallow ICMP?   According to my firewall docs, I can turn it off and it will: &lt;BR /&gt;&lt;BR /&gt;#drop "bad" icmp -- not replying to&lt;BR /&gt;# echo requests but still allowing internal&lt;BR /&gt;# pings to work correctly.&lt;BR /&gt;# It will accept destination-unreachable,&lt;BR /&gt;# time-exceeded, and echo-reply -- and&lt;BR /&gt;# drop the rest&lt;BR /&gt;&lt;BR /&gt;Will this cause any forseeable problems?</description>
      <pubDate>Wed, 21 May 2003 14:10:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978430#M575580</guid>
      <dc:creator>Ron Bombard</dc:creator>
      <dc:date>2003-05-21T14:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unsolicited Echo Reply</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978431#M575581</link>
      <description>I'd turn it off at the firewall.  It shouldn't bother anything.  Worse case you get a call from your ISP saying his Openview went red and you will have to allow it from him but from what you say it won't stop your unexpected echo replies (if they are really coming from the outside) unless you have a filter which drops all incoming packets with a local source address. (You should have such a filter anyway.)&lt;BR /&gt;&lt;BR /&gt;If you already have such a filter or if after adding one they continue to show up then it could be that for some reason the echo requests are going through a different switch than the replies and that is why they are being flagged.  Do your PCs and such have multiple NICs?&lt;BR /&gt;&lt;BR /&gt;Could also be a bug in the code which gives false positives.  What kind of switch and what version of code are you running?&lt;BR /&gt;&lt;BR /&gt;Ron</description>
      <pubDate>Wed, 21 May 2003 14:45:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978431#M575581</guid>
      <dc:creator>Ron Kinner</dc:creator>
      <dc:date>2003-05-21T14:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: Unsolicited Echo Reply</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978432#M575582</link>
      <description>I don't have any pcs with multiple nics.  except for one linux server thats used for a internet proxy and firewall.&lt;BR /&gt;&lt;BR /&gt;As for my switches and firmware: This is happening on multiple switches.  They are all HP Procurve switches with the latest firmware (as of last week). &lt;BR /&gt;&lt;BR /&gt;I'll turn off that ICMP at the firewall and see what happens.&lt;BR /&gt;&lt;BR /&gt;Thanks for the suggestions!</description>
      <pubDate>Wed, 21 May 2003 15:04:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/unsolicited-echo-reply/m-p/2978432#M575582</guid>
      <dc:creator>Ron Bombard</dc:creator>
      <dc:date>2003-05-21T15:04:58Z</dc:date>
    </item>
  </channel>
</rss>

