Hi. I have gotten attacked on my server by an attack based on flooding the network interface with ICMP packets. I do not know what this means, the support told me this. How is this happening and what is the best thing to do ? Thanks.
Sorry, I would be happy if a mod can move it Its a VPS at Servint, I expect them to have proper firewalls.
You should have your own layer of firewall. You willing to pay for a installations/configuring of a proper firewall?
Are you using Cisco routers? This came up in Google Cisco - Characterizing and Tracing Packet Floods Using Cisco Routers Most of the traffic that arrives on the serial interface consists of ICMP echo reply packets. This is probably the signature of a smurf attack, ... www.cisco.com/warp/public/707/22.html - 41k - Cached - Similar pages