Forum Discussion

Kasem_Badwi_144's avatar
Kasem_Badwi_144
Icon for Nimbostratus rankNimbostratus
Jun 04, 2014

F5 Self IPs are making ping scan with a huge concern Index as per Lancop report - Ping_Scan

Hi, I have multiple VLANs in LTM, as per the security team that F5 Self IPs are making ping scan with a huge concern Index as per Lancop report, example below : 5/19/2014 23:59Catch All10.2.1.810.15.4.0/2411819592Ping_Scan(23592) 5/19/2014 23:59Catch All10.2.1.910.15.4.0/2411104164Ping_Scan(22164)

 

Can u please advice what is this behavior? and Is it normal ?

 

Regards, Kasem

 

4 Replies

  • They could be misinterpreting ICMP type health monitors as ping scans. These health monitors would source from your non-floating self IP addresses. Do you have any pools using ICMP type monitoring?

     

    • Kasem_Badwi_144's avatar
      Kasem_Badwi_144
      Icon for Nimbostratus rankNimbostratus
      yes I am monitoring using the ICMP type, all-most all pools using ICMP monitoring pool.
    • Cory_50405's avatar
      Cory_50405
      Icon for Noctilucent rankNoctilucent
      Then it sounds like you have legitimate ICMP traffic, as long as it's sourcing from the non-floating self IP address on your LTM.