Hi
We are using Snort and get follwoing log message:
06/23-19:21:41.146900 12.107.140.x -> x.x.x.x ICMP TTL:117 TOS:0x0 ID:17311 IpLen:20 DgmLen:28
Type:8 Code:0 ID:512 Seq:10288 ECHO
[Xref => http://www.whitehats.com/info/IDS162]
12.107.140.x is outside ip and not use by my company.
x.x.x.x is our inside server ip address. This ip address has a public ip address static setup in the PIX 515,permit only for one tcp port, no icmp permit for the static ip or PIX outside interface.
Why outside machines can send ICMP to the inside machine and PIX 515 not do protection? Does the attack to the PIX 515?
Please help
Thanks
ben