repeated ICMP connection attempts???

Good evening,

The last few days I have noticed repeated ICMP connection attempts in my firewall log from the same IP address block.

They are coming from Source Port Type(3) and directed to Destination Port Type(10).

All these ICMP attempts are coming from Source IPs 67.202.66.201-205 and aimed at the IP address listed when I explore my ipconfig /all.

Is this something directed at me that I should be worried about or is it directed towards my internet provider?

Thanks and regards,

2harts4ever

The source IP belongs to Steadfast Networks, a network hosting provider based in Chicago. So the first question to answer is, are you using any of this company’s services?

The ICMP Type 3 Code 10 is one of the many ‘Unreachable’ codes generated by ICMP. In this particular case, it probably indicates a poorly configured router that for whatever reason is filtering certain packets that your system is trying to send. These are simply status messages.

If you don’t wish to see these messages, create a global rule to filter them out. You may also need a similar rule for WOS, under Application rules.

The source IP belongs to Steadfast Networks, a network hosting provider based in Chicago. So the first question to answer is, are you using any of this company’s services? Not that I know of

The ICMP Type 3 Code 10 is one of the many ‘Unreachable’ codes generated by ICMP. In this particular case, it probably indicates a poorly configured router that for whatever reason is filtering certain packets that your system is trying to send. These are simply status messages.

If you don’t wish to see these messages, create a global rule to filter them out. I’ll try that

You may also need a similar rule for WOS, under Application rules.

I appreciate your imput.

Thanks and regards,

2harts4ever

When you make the filter rule in Global Rules then there is no need to make a rule for WOS.

WOS in practice means that CIS sees no program listening to this incoming traffic. If you filter that ICMP traffic you want see the WOS entry in your logs anymore.

EricJH,

I appreciate the added information.

Thanks and regards,

2harts4ever