Provided by Aanval (Snort & Syslog Intrusion Detection and Correlation Engine) www.aanval.com
--
| GEN:SID | 1:405 |
| Message | ICMP Destination Unreachable Source Host Isolated |
| Summary | This event is generated when An ICMP Source Host Isolated datagram is detected on the network. |
| Impact | This is an indication of improperly configured routing equipment or network host. RFC 1812 indicates that ICMP Type 3 ICMP Code 8 messages should never be generated. |
| Detailed Information | This rule generates informational events about the network. Routers should never generate ICMP Type 11 Code 8 as they are in violation of RFC1812. Large numbers of these messages on the network could indication routing problems, faulty routing devices, or improperly configured hosts. |
| Affected Systems | |
| Attack Scenarios | None Known |
| Ease of Attack | Numerous tools and scripts can generate these types of ICMP datagrams. |
| Corrective Action | This rule detects informational network information, no corrective action is necessary. |
| Additional References | None |
--
DID:423883
--
http://www.aanval.com/