[Dshield] [SPAM] Re: ICMP problems

Martin Forest martin at forest.gen.nz
Wed Jun 29 02:33:48 GMT 2005


Allen Kistler wrote:

>Martin Forest wrote:
>  
>
>>My firewall is not logging icmp type or code. All I have is protocol 1, 
>>ICMP. When I submit log files with source port and destination port as 0 
>>and protocol 1, the lines are rejected.
>>Does that mean that unless I specify icmp type, i can not submit blocked 
>>icmp?
>>...
>>
Fortigate 5050. It looks like a bug and I have reported it to Fortinet.
All my icmp lines are reported as 0, 0, including stuff as host/net not 
available etc.
All my icmp lines are rejected during import. :(
/Martin



More information about the list mailing list