Can someone explain what I am seeing in the following firewall hit entry:
==================
Wingate firewall hit report:
Time: 8/10/2007 11:53:11 AM
Reason: Blackholed
Source MAC address: 00-01-5C-22-2A-C2
Destination MAC address: 00-14-BF-54-25-BF
Source IP Address: 6.10.69.118 : N/A
Destination IP Address: 101.238.1.0 : N/A
Protocol: 0
Time-to-live: 0
=================
Notes:
* I am getting several of these per hour and they are all strange (very low first byte, 1,2,3,4, etc) IPs. The protocol is always "0".
* Neither IP is in my black hole list, in fact for the purpose of this question, I currently have only one black hole entry which is: 58.218.177.22 - 255.255.255.255. If I remove this entry the firewall hits stop, but other IPs cause this as well.
* The destination address is not mine but the Destination MAC address is that of my cable modem which resides on my Wingate machine. In "normal" firewall hit entries the destination IP is always my assigned internet IP.
Do these entries actually mean something or are they a bug of some sort that I should ignore?
Thanks in advance!