cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2714
Views
11
Helpful
6
Replies

ICMP Network Sweep w/Echo from VPN

snowmizer
Level 1
Level 1

I am seeing occasional ICMP Network Sweep w/echo events from my IPS module. The attacker IP address is in our VPN range accessing internal servers (domain controller, server running our administration system). I don't think these are problems but I'm not sure.

Why would these be coming from VPN connections and why wouldn't they happen with everyone?

Thanks.

6 Replies 6

Justin Teixeira
Level 1
Level 1

Hi Snowmizer,

    There is nothing that I know of related to our VPN solutions that would cause the ICMP Network Sweep w/Echo signature to fire.  This signature simply means that the attacker IP pinged 5+ other addresses in succession.  You might want to check the IP(s) in question to see if they have any type of network management software installed as these are the usual benign triggers for this signature.  Otherwise, as the signature suggests, this might be a reconnaissance scan.

-JT

This appears to only be happening on one laptop in marketing when they are on the VPN so there aren't any network management tools installed on the laptop. It looks like it's always to the same servers. I can see references to port 135 or 445 for the IPs that are the targets.

Could this be part of the problem?

This is a normal pain signature that should be turned on the IPS using event action filters.

Don't have to worry much about it triggering for LAN or VPN clients

Regards

Farrukh

Thanks for the reply. I'll have to set some event action filters for this. My boss just asked me about it because it only appears to be happening with one person when they're on the VPN. Could be some software on their machine.

If that is the case, I would recommend  to run wireshark or something similar to see what is triggering this on the host machine.

Regards

Farrukh

That was the suggestion I gave to our help desk staff. Not sure what came out of it or if it was done. I guess if it continues to happen we'll have to get the machine again and do this.

Review Cisco Networking for a $25 gift card