Originally posted here by tolstoy
Right now I'm staring to run daily tcpdumps to try to see what the heck is in the packets that trigger these remote routers to respond with an ICMP message. Hopefully its all benign stuff.
I agree, I believe these to be benign as well, we would just like to locate the root cause (other than the Ident stuff). We are currently running a 'snoop' on our firewall to see what that is going to tell us.

Cheers: