Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

ping of death msg from fire wall Clean domain controler origin

Posted on 2004-03-24
8
255 Views
Last Modified: 2013-12-19
I am trying to figure out why our firewall is detecting ICMP (ping of death) coming from one of our remote DC's Going to machines on the main network.  (different subnet).

What is the DC trying to get from these machines and how do you stop it.

Going crazy with all the auto alerts from the firewall it is polluting my e-mail

Thanks
0
Comment
Question by:WinkDB
8 Comments
 
LVL 31

Expert Comment

by:Gareth Gudger
ID: 10668237
Has it always been like this? If not, has anything changed recently? Any replication going on with this remote DC?
0
 

Author Comment

by:WinkDB
ID: 10668340
it is a one way replication from the main dc on the main subnet.  Sorry I do not know that much in terms of details.  

Thanks
0
 
LVL 32

Expert Comment

by:LucF
ID: 10668367
An ICMP is just a "hello, are you there" package.
How do you know it's meant as a ping of death?

I suggest you to just change the mailing rules so it doesn't report these.

Greetings,

LucF
0
Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

 
LVL 2

Expert Comment

by:ministry92
ID: 10668756
LucF is right, what problems is this causing?  I'm assuming you have AV running on the remote DC?  If so, just write it off to a bad trip and adjust your notification metrics.
0
 

Author Comment

by:WinkDB
ID: 10669752
I knew that much I guess.  I wanted to be more specific and figure out the on off for the ICMP in regards to the remote dc communcating to the main subnet.  Why does it only ask are you there to just a few machines for example three out of twenty or so machines running.

The firewall just sees the packet size and generaicaly alerts us to  a ping of death.  I am realy just trying learn what is going on.  I will get there  just turning off the alert from the firewall is too simple.  I guess it is not a crisis so do not worry about to much unless there is something I can learn from this.

Thanks
0
 
LVL 32

Expert Comment

by:LucF
ID: 10669803
>>The firewall just sees the packet size and generaicaly alerts us to  a ping of death.
Ok, now I understand.

Run a virusscan on the sending server: (even though you probably have allready one running on that server)

http://www3.ca.com/virusinfo/virusscan.aspx
http://housecall.trendmicro.com/ 

If you have no luck with it, use this tool and post the logfile (after edditing out your own domainname)
 http://209.133.47.200/~merijn/files/HijackThis.exe

LucF
0
 
LVL 7

Expert Comment

by:spareticus
ID: 10670213
Your DC's will ping each other to verify connectivity.  
If there is truly a ping of death coming from that DC, then that is malware of some type.
It won't have any real effect on today's systems, but i can imagine it is a pain to see all the alerts.
You might look at the following to ensure you have all the appropriate ports open for a DC on a firewall

http://support.microsoft.com/default.aspx?scid=http://support.microsoft.com:80/support/kb/articles/q179/4/42.asp&NoWebContent=1
0
 
LVL 2

Accepted Solution

by:
mbwortham earned 500 total points
ID: 10692876
You may also try updating firmware / software for your firewall.  It is not uncommon to see firewalls incorrectly identifying certain legit traffic patterns as an "attack".  The detection methods may be fixed in a newer revision.
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Have you ever set up your wireless router at home or in the office to find that you little pop-up bubble in the bottom right-hand corner of Windows read "IP Conflict - One of more computers on the network have been assigned the following IP address"…
Greetings, Experts! First let me state that this website is top notch. I thoroughly enjoy the community that is shared here; those seeking help and those willing to sacrifice their time to help. It is fantastic. I am writing this article at th…
This video shows how to quickly and easily add an email signature for all users on Exchange 2016. The resulting signature is applied on a server level by Exchange Online. The email signature template has been downloaded from: www.mail-signatures…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question