From owner-freebsd-net Mon Sep 11 10:48:23 2000 Delivered-To: freebsd-net@freebsd.org Received: from bmah-freebsd-0.cisco.com (bmah-freebsd-0.cisco.com [171.70.84.42]) by hub.freebsd.org (Postfix) with ESMTP id 2339B37B423 for ; Mon, 11 Sep 2000 10:48:20 -0700 (PDT) Received: (from bmah@localhost) by bmah-freebsd-0.cisco.com (8.11.0/8.11.0) id e8BHlga36000; Mon, 11 Sep 2000 10:47:42 -0700 (PDT) (envelope-from bmah) Message-Id: <200009111747.e8BHlga36000@bmah-freebsd-0.cisco.com> X-Mailer: exmh version 2.2 06/23/2000 with nmh-1.0.4 To: Ian Smith Cc: Emmanuel Gravel , freebsd-net@FreeBSD.ORG Subject: Re: Strange TTL Exceeded messages In-Reply-To: References: Comments: In-reply-to Ian Smith message dated "Mon, 11 Sep 2000 06:53:36 +1000." From: "Bruce A. Mah" Reply-To: bmah@FreeBSD.ORG X-Face: g~c`.{#4q0"(V*b#g[i~rXgm*w;:nMfz%_RZLma)UgGN&=j`5vXoU^@n5v4:OO)c["!w)nD/!!~e4Sj7LiT'6*wZ83454H""lb{CC%T37O!!'S$S&D}sem7I[A 2V%N&+ X-Image-Url: http://www.employees.org/~bmah/Images/bmah-cisco-small.gif X-Url: http://www.employees.org/~bmah/ Mime-Version: 1.0 Content-Type: multipart/signed; boundary="==_Exmh_73906284P"; micalg=pgp-sha1; protocol="application/pgp-signature" Content-Transfer-Encoding: 7bit Date: Mon, 11 Sep 2000 10:47:42 -0700 Sender: owner-freebsd-net@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org --==_Exmh_73906284P Content-Type: text/plain; charset=us-ascii If memory serves me right, Ian Smith wrote: > On Sun, 10 Sep 2000, Emmanuel Gravel wrote: > > I know that icmp ttl exceeded messages are common with a traceroute, > > however why would I get so many from the same host (in a normal situation, > > considering I would have actually done a traceroute, which isn't the case) > ? > > Can't imagine. Hi-- I'm coming in to the middle of this thread (which I think probably belongs on -security anyways), but: 1) traceroute(1) can be told how many probe packets to send per hop. 2) There exist other programs that look like traceroute, but send many more packets per hop. In particular, the family of programs that includes pchar, pathchar, and clink, which are all experimental tools for network path characterization. I haven't a clue as to whether any of this information applies to the situation being discussed though. Bruce. --==_Exmh_73906284P Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: PGPfreeware 5.0i for non-commercial use MessageID: R6Q45eI5m5gjzFJqBkFpdFEO6eukCUSz iQA/AwUBOb0avtjKMXFboFLDEQI8HgCgv1Hq3HD5N5jqe9wSrk1uV7rXQNsAnA0k s7U4ug294Q5E9kxG0gtB7Ugk =fp4S -----END PGP SIGNATURE----- --==_Exmh_73906284P-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-net" in the body of the message