Without knowing more about your network and the rest of the content of the log entries you refer to, it’s hard to say if it is “normal” to see source IP 0.0.0.0 in your log entries.
For instance, Bootp/DHCP packets will have a source IP of 0.0.0.0, port 68 to destination IP 255.255.255.255, port 67. These packets are most likely harmless, and quite normal on a network using DHCP.
However, I have also seen log entries with source IP 0.0.0.0, 0 to dest. IP 0.0.0.0, 0, which turned out to be an insider attempt to covertly map my network. Too bad he forgot to spoof his MAC address ;-)
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.