[Bro] icmp_time_exceeded

Vern Paxson vern at icir.org
Wed Feb 16 14:26:22 PST 2005


> isn't there a possibility (an event) to recognize icmp requests dropped
> by the firewall.

Do you mean ICMP unreachables with "administratively prohibited" as the
subcode?  Those should generate icmp_unreachable events *if* the firewall
is configured to send the ICMPs (it might instead just silently drop).

		Vern



More information about the Bro mailing list