Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Network Security: Firewall, NAT, QoS, IPS and more

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-20-2004, 10:08 AM
Junior Member
 
Join Date: Jun 2003
Location: Denmark
Posts: 6
Default IP-Spoofing in packet filter log - help please

Hello,
We're using ASL 4.021, 3 NICs, external/LAN/DMZ and just got this on packet filter:

2004-Feb 20 10:02:36 (none) kernel: IP-SPOOFING Drop: IN=eth1 OUT= MAC=00:50:04:61:8f:9c:00:06:2a:a0:14:38:08:00 SRC=192.168.0.23 DST=***.***.***.*** LEN=78 TOS=0x00 PREC=0x00 TTL=118 ID=8073 PROTO=UDP SPT=1028 DPT=137 LEN=58

or, in LiveLog form,

10:02:36 IP-SPOOFING Drop 192.168.0.23 1028 -> ***.***.***.*** 137 UDP IP SPOOFING
SRC HW 00:50:04:61:8f:9c:00
DST HW 06:2a:a0:14:38:08:00

eth1 is our external interface, ***.***.***.*** is the world (WAN) IP on eth1. There is no machine at 129.168.0.23 on the LAN. The MAC address of the eth1 NIC is 00:50:04:61:8F:9C, corresponding to the source MAC address logged. The destination MAC address does not seem familiar.

Despite doc perusing and Googling, it is still not clear to me exactly what has been attempted and what, if any, consequences we should take. I'd be grateful if someone could elucidate. Thanks for reading.
Reply With Quote
  #2 (permalink)  
Old 02-20-2004, 10:33 AM
Senior Member
 
Join Date: Oct 2002
Location: Ljubljana, Slovenia
Posts: 233
Default Re: IP-Spoofing in packet filter log - help please

As you can see from log address 192.168.0.23 is comming to eth1.
Spoofing means that to eth1 commes IP which is not in the network of eth1.

And this must be Windows mashine, since it is sending netbios packets.

BR, Matjaz
Reply With Quote
  #3 (permalink)  
Old 02-21-2004, 06:53 PM
Gert Hansen's Avatar
Wizard
 
Join Date: Nov 2000
Location: Karlsruhe, Germany
Posts: 1,242
Default Re: IP-Spoofing in packet filter log - help please

Hi there,

this mostly happens if you connect multiple interfaces with the same hub or switch.

is that the case?

regards
Gert
Reply With Quote
  #4 (permalink)  
Old 02-21-2004, 10:38 PM
Junior Member
 
Join Date: Jun 2003
Location: Denmark
Posts: 6
Default Re: IP-Spoofing in packet filter log - help please

Nope,
there *is* a switch on the LAN side, but the only thing going in to it is Astaro's LAN interface; 3 user PCs beyond it. The DMZ interface goes direct to a mail/http server. LAN and DMZ are of course on separate, 'private' subnets, 192.168.0.0 and 192.168.2.0, respectively.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 11:08 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.