[Dshield] Multicasts from your ISP
afrayer at frayernet.com
Tue Feb 24 16:52:05 GMT 2004
One of my clients has been steadily logging multicasts (dest. 18.104.22.168,
port 520) from an IP belonging to their small ISP. The nature of the
multicasts suggests a router that is trying to discover a new route
through RIP, but the multicasts have been occurring for a week.
I e-mailed the ISP and got no response, and my client is too clueless to
speak to the ISP directly.
So far it looks like DShield is throwing out the log entries, but I
wonder if this is a situation that can simply be ignored (following a
stop at the client site to tweak the DShield filter to stop sending
those log entries), or if this is a situation that requires more
aggressive contact requests?
Alan Frayer,CNE,CNI,CIW CI,MCP,Net+ - afrayer at frayernet.com
Member: Independent Consultants Association (ICA)
Consultants - FREE Directory Listing - http://www.ica-assn.org
More information about the list