Could be GRE, IGMP, anything really.. running netflow would probably let you know real quick nm On Tue, 8 Dec 1998, Thom Youngblood wrote: > I've been tracking an attack all day long, and have been frustrated > trying to figure out both what was being attacked, and how. Finally, > I realized it was *not* ICMP, UDP, or TCP.