[unisog] Port 0

Florian Weimer fw at deneb.enyo.de
Thu Oct 27 16:59:38 GMT 2005


* Eric Christensen:

> I was reviewing my firewall logs this morning and found a few packets going
> to and from port 0.  Apparently they were ICMP packets.  I think that is
> probably legitimate but I'm thinking that many computers might accept these
> packets thinking they are legit when they are really attacks.  If they are
> just ICMP packets you could just block them.  Right?

What kind of logs?  Netflow data perhaps? 8-)


More information about the unisog mailing list