>
> > Hi everybody,
> >
> > i noticed this in dmesg and messages:
> >
> > kernel: IP_MASQ:reverse ICMP:failed checksum from 213.xxx.xxx.xxx!
> > last message repeated 1522 times.
> > Is this lvs specific (using nat) ? or can this be an attack?
> >
What is a reverse ICMP checksum? I'm assuming some kind of ICMP 'is it DoS'
validity check? Anyone know?
>
> I see those too
> Jun 17 22:16:19 wwc kernel: IP_MASQ:reverse ICMP: failed checksum from
> 193.203.8.8!
>
> not as many as you but every few hours a bunch.
>
Any relation to that IP being a proxy?
On a side note it's always amusing to me to see any reference to
'seabone'... ah the pirates of the internet :P .. are they still their own
continent? (or am I way off and thinking of the wrong thing?!)
13 181 ms 190 ms 180 ms mi5-ny2-racc5.seabone.net [195.22.205.134]
14 190 ms 181 ms 190 ms pa5-mi5-racc3.seabone.net [195.22.192.134]
15 191 ms 200 ms 190 ms fa-eth-2-pa1.seabone.net [195.22.205.249]
16 210 ms 210 ms 211 ms srbija-telekom-1-yu-pa1.seabone.net
[195.22.192.
162]
17 391 ms 340 ms 281 ms PTT2-NET.telekom.yu [195.178.34.50]
18 421 ms 431 ms 480 ms BITS-7507.ptt.yu [212.62.38.78]
19 541 ms 501 ms 440 ms proxy.bitsyu.net [193.203.8.8]
Cheers & happy monday.. (if possible)
Peter
|