NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FW1] local interface address spoofing



Hi everyone,

today my firewall started dropping one packet from 127.0.0.1(local
interface) to 255.255.255.255 (broadcast), service 2301 udp (Compaq Insight
Manager), but only on interfaces directing to my local net and the dmz. No
packets are dropped from or to other nets. Logviewer says the packets were
dropped because of local interface address spoofing (Rule 0), now this
happens exactly every 5 minutes. I've got about 25 Compaq servers and 500
Compaq Deskpro Clients within the local net and a couple of Compaq Servers
on the dmz. The servers all got CIM installed, but those Agents are running
for weeks, months, years now without any problems. Has anyone (using Compaq
Servers) seen something like this before? My logfile's getting flooded by
those entries. By the way, i'm running Checkpoint FW-1 SP4, all patches
installed. Any ideas?

tia

Dirk



================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.