Hello and thanks for reading this. I have been getting a lot of spoof alarms lately and I was hoping someone can help me interpret them. A sample is provided below.
Jun 25 10:57:31 pri=4 flt_type=default flt_action=block msg="Possible spoof, return interface xl2 doesn't match arrival interface" proto=445/tcp src=202.100.200.140 srcport=1081 dst=24.139.7.26 dstport=445 interface=xl0 flags=0x2 Thanks in advance. John R. ******************************************** The information contained in this e-mail and document(s) attached are for the exclusive use of the addressee and may contain confidential, privileged and non-disclosable information. If the recipient of this e-mail is not the addressee, such recipient is strictly prohibited from reading, photocopying, distributing or otherwise using this e-mail or its content in any way. ------------------------------------------------------ To unsubscribe: [EMAIL PROTECTED] For additional commands: [EMAIL PROTECTED] Archive: http://www.mail-archive.com/[EMAIL PROTECTED]
