I recently started seeing these entries in my firewall log.
SonicWALL 0040-100E-A2CB Log (part 1) dumped to email at 02/22/2001
12:21:51.064
02/22/2001 08:19:29.928 - IP spoof detected -
Source:192.168.100.1, 137, WAN - Destination:204.216.xxx.xxx, 137,
LAN - MAC address: 00.E0.1E.3E.9E.AF -
The destination address is my mail (exchange) server. The source address is
sometimes different but always in the 192.168.0.0 range and the MAC address
is always the same.
I am no expert on this stuff but I do know what IP spoofing is. What I don't
understand is why I'm getting source addresses of 192.168.x.x on my WAN /
Internet interface that are all from the same MAC but with different IP's.
Thanks in advance for any help that is offered.
David Loysen
Sr. Network Engineer
The Corky McMillin Companies
David Loysen
Sr. Network Engineer
The Corky McMillin Companies
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]