ICMP Overloading Argus

Eric eric-list-argus at catastrophe.net
Wed Aug 20 11:44:18 EDT 2003


We're seeing argus die off with the following errors on FreeBSD
5.1

(argus), uid 0: exited on signal 6 (core dumped)

This is due to the huge spikes of icmp traffic in the past few
days. 

Besides not capturing ICMP, can I do anything to help make argus
more resilient to these problems? We notice that this happens
during W32.Slammer worms as well.

Thanks.

- Eric




More information about the argus mailing list