- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Unsolicited Echo Reply
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 05:00 AM
тАО05-21-2003 05:00 AM
Any idea what causes this, how to stop it, or is it something I should consern myself with? I probably get about 5 of these per day across all my switches.
Thanks for any info.
Ron Bombard, Network Admin.
Native Textiles Inc.
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 05:13 AM
тАО05-21-2003 05:13 AM
SolutionThis may help:-
http://docs.hp.com/cgi-bin/fsearch/framedisplay?top=/hpux/onlinedocs/B2355-90131/B2355-90131_top.html&con=/hpux/onlinedocs/B2355-90131/00/00/38-con.html&toc=/hpux/onlinedocs/B2355-90131/00/00/38-toc.html&searchterms=echo%7cUnsolicited&queryid=19030521-070836
Also is there one router that all of these devices go through? If so check it out.
Paula
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 05:36 AM
тАО05-21-2003 05:36 AM
Re: Unsolicited Echo Reply
See:
http://www.sans.org/resources/idfaq/traffic.php
Also check out the TFN exploit discussed at:
http://www.sans.org/resources/idfaq/icmp_misuse.php
Ron
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 05:52 AM
тАО05-21-2003 05:52 AM
Re: Unsolicited Echo Reply
ip:
An unsolicited ICMP reply to a ping was received from
The "not sent by the local switch" may help you.
Paula
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 05:54 AM
тАО05-21-2003 05:54 AM
Re: Unsolicited Echo Reply
http://www.iss.net/security_center/advice/Intrusions/2000109/default.htm
Paula
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 05:56 AM
тАО05-21-2003 05:56 AM
Re: Unsolicited Echo Reply
http://www.iss.net/security_center/advice/Intrusions/2000109/default.htm
and
Unsolicited echo-replies can be a sign of a Smurf ( http://www.cert.org/advisories/CA-1998-01.html)amplification attack.
Paula
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 06:00 AM
тАО05-21-2003 06:00 AM
Re: Unsolicited Echo Reply
Please assign points to your previous questions if the answers have assisted you:-
http://forums.itrc.hp.com/cm/TopSolutions/1,,CA302314!1!questions,00.html
;^)
Paula
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 07:10 AM
тАО05-21-2003 07:10 AM
Re: Unsolicited Echo Reply
My firewalls allow ICMP stuff, but limit them to 1 per 60 secs.
Is it recommended to disallow ICMP? According to my firewall docs, I can turn it off and it will:
#drop "bad" icmp -- not replying to
# echo requests but still allowing internal
# pings to work correctly.
# It will accept destination-unreachable,
# time-exceeded, and echo-reply -- and
# drop the rest
Will this cause any forseeable problems?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 07:45 AM
тАО05-21-2003 07:45 AM
Re: Unsolicited Echo Reply
If you already have such a filter or if after adding one they continue to show up then it could be that for some reason the echo requests are going through a different switch than the replies and that is why they are being flagged. Do your PCs and such have multiple NICs?
Could also be a bug in the code which gives false positives. What kind of switch and what version of code are you running?
Ron
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-21-2003 08:04 AM
тАО05-21-2003 08:04 AM
Re: Unsolicited Echo Reply
As for my switches and firmware: This is happening on multiple switches. They are all HP Procurve switches with the latest firmware (as of last week).
I'll turn off that ICMP at the firewall and see what happens.
Thanks for the suggestions!