cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
452
Views
0
Helpful
1
Replies

Impossible IP packet: SIG 1102 (0) - (0.1.0.4 address)

andy.deakin
Level 1
Level 1

I have just noticed that this signature has fired for 2 of our different clients but with the same source/ destination IP's. I would normally assume that this is either impossible or very strange.

I think that might be where the name of the signature comes from anyway?

In each case all IP addresses reported, were 0.1.0.4.

Is this a generic address that simply represents an internal unknown device?

Does the signature need tweaking on the sensor? How are we meant to advise the client of where this activity comes from?

And finally, does it require a TAC case to request an update from Cisco?

It slightly concerns me that this signature has an impact rating of high, and we've not noticed this before, and every instance has been ignored (not filtered, etc).

Any help would be appreciated.

Regards.

1 Reply 1

andy.deakin
Level 1
Level 1

The nature of this signature is an attempt to crash the device by having an IP packet with equal S & D. It is known as the Land attack, but does it matter what the IP's actually are?

If it can never occur within legitimate traffic, then can we always ignore.

Cheers.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card