[Snort-users] Source IP 18.104.22.168
ed at ...11248...
Sun Feb 22 12:01:01 EST 2004
Has anyone ran into seeing tons of traffic from this IP? I setup snort on my redhat box acting as
a my router for my cable modem. I see TONS of traffic from 22.214.171.124 to 0.0.0.0 The signature
lists as "snort\_decoder) WARNING: Not IPv4 datagram!", Layer 4 Protocol: 48
I've seen about 5000 packets in the past 8 hours. WHOIS informaion shows as being IANA Reserved...
Any ideas? Maybe the cable provider is using this as a broadcast for some dumb reason?
More information about the Snort-users