Hi,
I am seeing a new type, to me, of ICMP packets arriving here. At first it was one site sending but now a few sites are sending these packets.
The packets, as reported by my firewall, have the form:-
Source:63.188.36.251, 1026, WAN - Destination: a.b.c.d, 6284, WAN - Type: 1026 -
This sample comes from Sprint IP range but I am seeing them from other ranges as well.
From the earlier discussion on Destination unreachable packets these are Type
1026 Code 6284. The type numbers seen are 1026 and 1027 but there is a wide variation in the code numbers and the forewall may be reporting the port number attacked.
I couldn't see anything in either RFC 792 or 950 to explain them.
The firewall is dropping them so I am safe from whatever is being tried on. However, I am interested in what they are and what is being attempted.
Can anyone let me know what they are?