Hello and thanks for reading this.

I have been getting a lot of spoof alarms lately and I was hoping someone
can help me interpret them.
A sample is provided below.

Jun 25 10:57:31 pri=4 flt_type=default flt_action=block msg="Possible spoof,
return interface xl2 doesn't match arrival interface" proto=445/tcp
src=202.100.200.140 srcport=1081 dst=24.139.7.26 dstport=445 interface=xl0
flags=0x2

Thanks in advance.

John R.

******************************************** 
The information contained in this e-mail and document(s) attached are for
the exclusive use of the addressee and may contain confidential, privileged
and non-disclosable information.  If the recipient of this e-mail is not the
addressee, such recipient is strictly prohibited from reading, photocopying,
distributing or otherwise using this e-mail or its content in any way.

------------------------------------------------------
To unsubscribe:           [EMAIL PROTECTED]
For additional commands:         [EMAIL PROTECTED]
Archive:  http://www.mail-archive.com/[EMAIL PROTECTED]

Reply via email to