\_ They are probably running in stealth mode. \_ They do not reply to pings. \_ \_ I would probably recommend to drop all packets coming \_ from that host. \_ -> [...] \_ -> The IP address hasn't changed, ip 146.83.240.200 is telling \_ -> you that it can't \_ -> reach that host. That is the last system in the route to \_ -> get to 200.1.28.20. Consider also that it may be spoofed, and that perhaps your default policy should be DENY or REJECT. :-) David