[Dshield] ICMP Redirect?

David Vincent david.vincent at mightyoaks.com
Thu Jun 12 05:28:52 GMT 2003

can anyone tell me why I would be receiving these in my firewall logs?

three in a row.  first one, then another three seconds later, then another
six seconds later...

Time: 06/11/2003, 22:00:30
Message: ICMP Redirect
Destination:xxx.xxx.xxx.xxx, Type:5, Code:0 (from WAN Inbound)

that's about all the detail it provides, a little skimpy to say the least.
could this be a side-effect of p2p?

that's all that I can see which would be generating any sort of traffic i
could consider a load (and even that's throttled to 10k/s, a pittance!).
tho I do have http, smtp, pop3, and a few remote control tools operating on
different ports.  there's nothing resembling this ip in the logs.



(ooo!  the dirty cross-poster)

