cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
295
Views
0
Helpful
1
Replies

IDS with PIX 515 static map

bma
Level 1
Level 1

Hi

We are using Snort and get follwoing log message:

06/23-19:21:41.146900 12.107.140.x -> x.x.x.x ICMP TTL:117 TOS:0x0 ID:17311 IpLen:20 DgmLen:28

Type:8 Code:0 ID:512 Seq:10288 ECHO

[Xref => http://www.whitehats.com/info/IDS162]

12.107.140.x is outside ip and not use by my company.

x.x.x.x is our inside server ip address. This ip address has a public ip address static setup in the PIX 515,permit only for one tcp port, no icmp permit for the static ip or PIX outside interface.

Why outside machines can send ICMP to the inside machine and PIX 515 not do protection? Does the attack to the PIX 515?

Please help

Thanks

ben

1 Reply 1

s-doyle
Level 3
Level 3

Did you check the bug tool kit for any known bugs??

Review Cisco Networking for a $25 gift card