> >What sort of attack is this? What are you seeing in your firewall logs? > >To restrict all incoming new and established state ICMP traffic you can >do something like: > >iptables -A INPUT -p icmp -m state --state NEW,ESTABLISHED,RELATED -j DROP > i cant even SSH to see whats going on..... its with my ISP they told me its under a DDOS attack and some one trying to loin in via SSH.... if i block all icmp would that help ? ------- Web Hosting at a cheap price, starting at $1 per month with your own domain, .COM, .NET, .LK, .ORG etc.. PHP, CGI, Perl, MySQL, Cpanel 9, POP3, POP3s, SMTP, IMAP, FTP, http://www.orbitsl.net - : send the line "unsubscribe linux-admin" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html