[clug] Dropped icmp packets - means what?

Kim Holburn kim.holburn at anu.edu.au
Fri Aug 22 10:25:36 EST 2003

At 10:07 AM +1000 03/8/22, Peter Barker wrote:
>On Thu, 21 Aug 2003, Felix Karpfen wrote:
>> Attached is a log of the packets that were dropped by "iptables" today.
>Those are "ICMP echo" packets. The "ping" program will cause these to be
>generated. They are basically an "is anyone there" query. And before you
>ask, not answering is a bad idea, if you are there :-)

Not at all.  If you are a server or a router answering a ping is usually a good idea otherwise not answering is a good idea generally since there are few good reasons to let most people on the internet know you are there.

> > While the information in "man icmp" is well over my head, it did sound
>> to me that icmp messages relate to kernel activities and ought to be
>> internal to either the computer or - at least - to the network to which
>> the computer is attached.
>icmp is part of the glue which holds everything together. Or, at least,
>tells you when everything is falling apart.
>http://www.faqs.org/docs/iptables/icmptypes.html gives a list of icmp
>packet types.
>> Hence I am puzzled by the IP addresses of many of the dropped packages -
>> I have difficulty in relating these addresses to my ISP (WebOne).
>They're probably just people looking for machines to exploit. Nothing to
>worry about ;-P
>> Since WebOne has figured prominently in recent postings to this list, I
>> thought it worth forwarding my log for <inspection|comment>.
>WebOne are not responsible for this. Try looking up the "source" ip
>pbarker at milligan:~$ host
> domain name pointer
>pbarker at milligan:~$ host
> domain name pointer
>pbarker at milligan:~$ host
> domain name pointer
>pbarker at milligan:~$
>Just make sure your machine is up-to-date. And relax - the internet's a
>nasty place :-)
>> Felix Karpfen
