Hello all, Recently I've been seeing log entrys on my NG3 box show up on my external interface with a source of "localhost". A snoop shows source port 80 to various IPs and ports in the 1000-2000 range. They are being dropped by rule 0, but I do not recall ever seeing this behavior before. Is this a spoof attempt?
Thanks, Hal ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
