Snort mailing list archives

Source IP 173.80.0.0


From: "Ed" <ed () eddo net>
Date: Sun, 22 Feb 2004 14:52:54 -0500

Greetings -

Has anyone ran into seeing tons of traffic from this IP?  I setup snort on my redhat box acting as
a my router for my cable modem.  I see TONS of traffic from 173.80.0.0 to 0.0.0.0  The signature
lists as "snort\_decoder) WARNING: Not IPv4 datagram!", Layer 4 Protocol: 48

I've seen about 5000 packets in the past 8 hours.  WHOIS informaion shows as being IANA Reserved...
 http://ws.arin.net/cgi-bin/whois.pl?queryinput=173.80.0.0

Any ideas?  Maybe the cable provider is using this as a broadcast for some dumb reason?

Thanks,
Ed


Current thread: