 |

06-12-2009, 08:46 PM
|
|
Member
|
|
Join Date: Sep 2005
Posts: 34
|
|
Help with spoofed packet from myself
running 7.403 and recently just added my Business class cable modem so i have 13 ipaddresses, to the multipath uplink balancing feature and like it. So here is my problem i would test access to the vpn from a laptop plung into the router that was on the cable modem and i would test access as if i was outside the building. Now i can't connect to anything vpn or my webservers because in the packet filter it detects a spoofed address, which i had reseaved just one for a cheep dlink router plug into the cable modem but it is the same subnet since i only have one router on the modem so even though i don't use that address or have it setup on astaro.
I turned off the spoof check and all works, but i don't want to do that, I looked for a way to not check for spoof from one ipaddress, like you can add an execption in IPS and can't find.
So the question is how can i fix this ? i don;t think i can subnet my cable modem addresses since i only have the one gateway on the modem itself, thanks for any insight into this problem..
|

06-12-2009, 09:45 PM
|
|
Moderator
|
|
Join Date: Jul 2001
Location: southern California
Posts: 5,152
|
|
Hi Barry, do you have spoof checking set to normal or strict?
Which IPs does it think are spoofed? on the WAN subnet or DMZ?
Barry G
__________________
http://DealBert.net
Home & business end-user since v1.x - ASL 6.3x, HP DL145 Dual Opteron, 1GB RAM, 6 gigE NICs, 50-IP Platinum License
- ASL 7.3x, Dell PE1550 Dual PIII 1GHz, 1GB RAM, 2 NICs, 50-IP Platinum License
- ASL 7.5x, 17-watt fanless mini-ITX system: MSI IM-945GSE-A Atom n270, 2GB RAM, Morex T3310 case. 2 Intel GigE, 3 VLANs. 80G 5200rpm 2.5" HD
Netgear GS108T gigE VLAN switch & Linksys WRT54G WAP
Total network infrastructure: 27 watts. 100-IP Home User. FiOS 10mb/2mb
|

06-12-2009, 10:05 PM
|
|
Member
|
|
Join Date: Sep 2005
Posts: 34
|
|
spoof checking is normal
my dlink as a cable modem was side (a internet ip of x.x.x.26) which is trying to get to the WAN side of astaro on a t-1, ethier a vpn connection or a website, But i have a second interface with a ipaddress for cable modem of x.x.x.25 in the same subnet of the .26 and both gateways is .17.
So .26 is in packet filter trying to get to my net line which is a t-1
|

06-13-2009, 09:27 PM
|
|
Moderator
|
|
Join Date: Jul 2001
Location: southern California
Posts: 5,152
|
|
You shouldn't have 2 interfaces on the same switch/network; I think that is the problem.
Barry
__________________
http://DealBert.net
Home & business end-user since v1.x - ASL 6.3x, HP DL145 Dual Opteron, 1GB RAM, 6 gigE NICs, 50-IP Platinum License
- ASL 7.3x, Dell PE1550 Dual PIII 1GHz, 1GB RAM, 2 NICs, 50-IP Platinum License
- ASL 7.5x, 17-watt fanless mini-ITX system: MSI IM-945GSE-A Atom n270, 2GB RAM, Morex T3310 case. 2 Intel GigE, 3 VLANs. 80G 5200rpm 2.5" HD
Netgear GS108T gigE VLAN switch & Linksys WRT54G WAP
Total network infrastructure: 27 watts. 100-IP Home User. FiOS 10mb/2mb
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT. The time now is 07:03 PM.
| |  |