NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW1] RULE SAM AND OTHERS



Hi,
--- San_Martín_Ranero_Carlos <[email protected]> a écrit : 
> 
> Hello:
> 
> I have a little problem. I was looking for the solution but I haven't
> found.
> 
> My question is:
> The FW1 Alerts window show me an error each 10 minutes aprox.
> 
> reject correct-address>.. alert proto udp src internal
> server(x.x.x.x)  dst
> x.x.255.255 service nbdatagram s_port  nbdatagram len 229 rule sam

Your firewall sees netbios datagram broadcasts and rejects them.
It might be an anti-spoofing rule set to 'alert'.
I saw this behaviour with a multi-homed NT server sending broadcasts on
one interface with the source IP of its other interface, thus raising
the anti-spoofing rule.
check what interface of your firewall is logged if that is the case.
In my case I totally removed the netbios service (using registry
editor) from the NT server and the messages have gone.

> 
> I don't know what it means.
> 
> Thank you


___________________________________________________________
Do You Yahoo!?
Achetez, vendez! À votre prix! Sur http://encheres.yahoo.fr


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents � 2003 Network Presence, LLC. All rights reserved.