Antwort: which application sends a ping?

From: Volker Gruenewald (Volker.Gruenewald@LINDE-MH.DE)
Date: Wed Oct 08 2003 - 03:07:38 EDT


Hi Frank,

Maybe this could be th pmtu discover function, which is enabled as default.
what does a
"/usr/sbin/no -o tcp_pmtu_discover"
"/usr/sbin/no -o udp_pmtu_discover"
say?

You can set it to 0 with

/usr/sbin/no -o tcp_pmtu_discover=0
/usr/sbin/no -o udp_pmtu_discover=0

regards,

---------------------------------------------------
Volker Grünewald
IT Administration
Linde AG, material handling
Aschaffenburg / Germany
volker.gruenewald@linde-mh.de
www.linde.com
---------------------------------------------------

|---------+--------------------------->
| | fmu@OERAG.DE |
| | Gesendet von: |
| | IBM AIX |
| | Discussion List |
| | <aix-l@Princeton|
| | .EDU> |
| | |
| | |
| | 10/07/03 04:13 |
| | PM |
| | Bitte antworten |
| | an IBM AIX |
| | Discussion List |
| | |
|---------+--------------------------->
>------------------------------------------------------------------------------------------------------------------------------|
  | |
  | An: aix-l@Princeton.EDU |
  | Kopie: |
  | Thema: which application sends a ping? |
>------------------------------------------------------------------------------------------------------------------------------|

Hi *,

one of our node sends to an IP adress (195.145.35.117) in irregular
distances a ping. I start an iptrace an obeserve only this:

Packet Number 37599
ETH: ====( 1514 bytes transmitted on interface en1 )==== 15:00:55.292370785
ETH: [ 00:02:55:9a:54:3c -> 00:09:b7:b5:e9:20 ] type 800 (IP)
IP: < SRC = 172.22.1.10 > (phoenix-eth)
IP: < DST = 195.145.35.117 >
IP: ip_v=4, ip_hl=20, ip_tos=0, ip_len=1500, ip_id=59506, ip_off=0 DF
IP: ip_ttl=255, ip_sum=f986, ip_p = 1 (ICMP)
ICMP: icmp_type=8 (ECHO_REQUEST) icmp_id=0 icmp_seq=0

Does somebody have an idea as I can find the program, which sends the ping?

Best regards,
Frank

This e-mail may contain confidential and/or privileged information.
If you are not the intended recipient (or have received this e-mail
in error) please notify the sender immediately and destroy this e-mail.
Any unauthorised copying, disclosure or distribution of the material
in this e-mail is strictly forbidden.
Any views expressed in this message are those of the individual
sender, except where the sender specifically states them to be
the views of Linde Material Handling.

Since January 2002 we use the e-mail domain linde-mh.de instead
of linde-fh.de.

This mail has been swept for the presence of computerviruses.



This archive was generated by hypermail 2.1.7 : Wed Apr 09 2008 - 22:17:15 EDT