TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

Good day.

The Network sensor keeps track of all mac addresses passing thru. Also it
monitors Inbound and outbound traffic. It logs both source and destination
for facilitate our lives in tracking down a specific event. In the case of
IP duplicate, the source IP is in question, not the destination IP. 

I will say that this is a very nice feature in the IDS. The IP duplicate
event indicates that another device on your network is using and IP address
while another one is trying to acquire the same IP. 

The second scenario will be when you replace a faulty NIC on the network
without changing the IP address, Realsecure will see the IP address with a
mac address that is different from what it has on its ARP table for that IP
address. Realsecure will tag it as an IP duplicate event. 

The third Scenario will be when you bring up a new system on your network
and assign that system an IP address that was used by a previous system.
Since Arp entries are kept on the sensor, it will tag it as IP duplicate
event. 

Resolution: 

If you have done any of these on your network, please flush the arp table on
the IDS machine (on the Sensor not the Console) and shutdown and restart the
sensor from the Console and you will be in business.

Best

Cleo
=================================
Cleophas A. Toe
Sr. Information Security Officer
Yodlee, Inc.
Cell #: 510-858-9700
=================================

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
Sent: Monday, October 29, 2001 5:47 AM
To: [EMAIL PROTECTED]
Subject: IP�Duplicate



TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any
problems!
----------------------------------------------------------------------------

Hi,

I have a doubt about IPDuplicate event triggered by Network Sensor 6.0:

Which IP is the duplicate one: source IP or destionation IP ?
Why does RealSecure log two IPs (source/destionation) ?

Thanks,

Fernando




Reply via email to