Snort mailing list archives
Source IP 173.80.0.0
From: "Ed" <ed () eddo net>
Date: Sun, 22 Feb 2004 14:52:54 -0500
Greetings - Has anyone ran into seeing tons of traffic from this IP? I setup snort on my redhat box acting as a my router for my cable modem. I see TONS of traffic from 173.80.0.0 to 0.0.0.0 The signature lists as "snort\_decoder) WARNING: Not IPv4 datagram!", Layer 4 Protocol: 48 I've seen about 5000 packets in the past 8 hours. WHOIS informaion shows as being IANA Reserved... http://ws.arin.net/cgi-bin/whois.pl?queryinput=173.80.0.0 Any ideas? Maybe the cable provider is using this as a broadcast for some dumb reason? Thanks, Ed
Current thread:
- Source IP 173.80.0.0 Ed (Feb 22)
- Re: Source IP 173.80.0.0 ypwhich (Feb 24)
- Re: Source IP 173.80.0.0 [revisited], bug? Ed (Mar 02)
- RE: Source IP 173.80.0.0 [revisited], bug? Fred McFeeters (Mar 02)
- Re: Source IP 173.80.0.0 [revisited], bug? ypwhich (Mar 02)
- Re: Source IP 173.80.0.0 [revisited], bug? Ed (Mar 02)
- Re: Source IP 173.80.0.0 ypwhich (Feb 24)