TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any problems!
----------------------------------------------------------------------------

Hi Wei,

It depends!!!
Are working in a switch environment? Are you hard coding the mac addresses
on the switch?
A VIP is directly bound to a physical device (MAC) redistributing traffic to
server farms' machines.
A packet coming from the physical server will loose the MAC address at the
first hop. Therefore this should not be the problem you are seeing on your
network. If the "godly" RS network Sensor is sitting a hop away and
monitoring traffic coming from/to the servers farm the mac address will be
cash by the sensor and it will be the mac address the VIP is bound to. This
first scenario assume that you have one single virtual IP for the MAC
address.

The second scenario is that "Wonderful" sun machines allow you to have
multiple virtual interfaces on the mac. Then RealSecure will be completely
confused and alarm you of lot of IPDuplicate events. At this point, I do not
believe that ISS as a fix for this due to the way RealSecure detects
IPDuplicate (It cashes the MAC address and match the IP addresses to it).

Qui dit mieux???
Bon appetit

Cleo

-----Original Message-----
From: Zhao Wei [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, October 30, 2001 5:51 PM
To: Cleophas Toe; [EMAIL PROTECTED]; [EMAIL PROTECTED]
Cc: [EMAIL PROTECTED]
Subject: Re: IP�Duplicate



TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any
problems!
----------------------------------------------------------------------------

Hi Toe,

We face the IP duplicate too, but no in the scenarios you have mentioned. It
is always alert on the SUN Solaris machine, also we didn't really add new ip
or machines in the same network. Does this related the way Solaris handling
Virtual IP mac address?

Thank you and regards,

Zhao Wei
----- Original Message -----
From: "Cleophas Toe" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]>
Cc: <[EMAIL PROTECTED]>
Sent: Tuesday, 30 October, 2001 5:41 AM
Subject: RE: IP�Duplicate


> ***************************************** (on blackcomb)
>
> noname was scanned and no virus found.
> *********************************************************
>


----------------------------------------------------------------------------
----



TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any
problems!
----------------------------------------------------------------------------

Good day.

The Network sensor keeps track of all mac addresses passing thru. Also it
monitors Inbound and outbound traffic. It logs both source and destination
for facilitate our lives in tracking down a specific event. In the case of
IP duplicate, the source IP is in question, not the destination IP.

I will say that this is a very nice feature in the IDS. The IP duplicate
event indicates that another device on your network is using and IP address
while another one is trying to acquire the same IP.

The second scenario will be when you replace a faulty NIC on the network
without changing the IP address, Realsecure will see the IP address with a
mac address that is different from what it has on its ARP table for that IP
address. Realsecure will tag it as an IP duplicate event.

The third Scenario will be when you bring up a new system on your network
and assign that system an IP address that was used by a previous system.
Since Arp entries are kept on the sensor, it will tag it as IP duplicate
event.

Resolution:

If you have done any of these on your network, please flush the arp table on
the IDS machine (on the Sensor not the Console) and shutdown and restart the
sensor from the Console and you will be in business.

Best

Cleo
=================================
Cleophas A. Toe
Sr. Information Security Officer
Yodlee, Inc.
Cell #: 510-858-9700
=================================

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
Sent: Monday, October 29, 2001 5:47 AM
To: [EMAIL PROTECTED]
Subject: IP�Duplicate



TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to
[EMAIL PROTECTED]  Contact [EMAIL PROTECTED] for help with any
problems!
----------------------------------------------------------------------------

Hi,

I have a doubt about IPDuplicate event triggered by Network Sensor 6.0:

Which IP is the duplicate one: source IP or destionation IP ?
Why does RealSecure log two IPs (source/destionation) ?

Thanks,

Fernando








Reply via email to