TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ----------------------------------------------------------------------------
Hi Wei, It depends!!! Are working in a switch environment? Are you hard coding the mac addresses on the switch? A VIP is directly bound to a physical device (MAC) redistributing traffic to server farms' machines. A packet coming from the physical server will loose the MAC address at the first hop. Therefore this should not be the problem you are seeing on your network. If the "godly" RS network Sensor is sitting a hop away and monitoring traffic coming from/to the servers farm the mac address will be cash by the sensor and it will be the mac address the VIP is bound to. This first scenario assume that you have one single virtual IP for the MAC address. The second scenario is that "Wonderful" sun machines allow you to have multiple virtual interfaces on the mac. Then RealSecure will be completely confused and alarm you of lot of IPDuplicate events. At this point, I do not believe that ISS as a fix for this due to the way RealSecure detects IPDuplicate (It cashes the MAC address and match the IP addresses to it). Qui dit mieux??? Bon appetit Cleo -----Original Message----- From: Zhao Wei [mailto:[EMAIL PROTECTED]] Sent: Tuesday, October 30, 2001 5:51 PM To: Cleophas Toe; [EMAIL PROTECTED]; [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Subject: Re: IP�Duplicate TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ---------------------------------------------------------------------------- Hi Toe, We face the IP duplicate too, but no in the scenarios you have mentioned. It is always alert on the SUN Solaris machine, also we didn't really add new ip or machines in the same network. Does this related the way Solaris handling Virtual IP mac address? Thank you and regards, Zhao Wei ----- Original Message ----- From: "Cleophas Toe" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]> Cc: <[EMAIL PROTECTED]> Sent: Tuesday, 30 October, 2001 5:41 AM Subject: RE: IP�Duplicate > ***************************************** (on blackcomb) > > noname was scanned and no virus found. > ********************************************************* > ---------------------------------------------------------------------------- ---- TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ---------------------------------------------------------------------------- Good day. The Network sensor keeps track of all mac addresses passing thru. Also it monitors Inbound and outbound traffic. It logs both source and destination for facilitate our lives in tracking down a specific event. In the case of IP duplicate, the source IP is in question, not the destination IP. I will say that this is a very nice feature in the IDS. The IP duplicate event indicates that another device on your network is using and IP address while another one is trying to acquire the same IP. The second scenario will be when you replace a faulty NIC on the network without changing the IP address, Realsecure will see the IP address with a mac address that is different from what it has on its ARP table for that IP address. Realsecure will tag it as an IP duplicate event. The third Scenario will be when you bring up a new system on your network and assign that system an IP address that was used by a previous system. Since Arp entries are kept on the sensor, it will tag it as IP duplicate event. Resolution: If you have done any of these on your network, please flush the arp table on the IDS machine (on the Sensor not the Console) and shutdown and restart the sensor from the Console and you will be in business. Best Cleo ================================= Cleophas A. Toe Sr. Information Security Officer Yodlee, Inc. Cell #: 510-858-9700 ================================= -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Sent: Monday, October 29, 2001 5:47 AM To: [EMAIL PROTECTED] Subject: IP�Duplicate TO UNSUBSCRIBE: email "unsubscribe issforum" in the body of your message to [EMAIL PROTECTED] Contact [EMAIL PROTECTED] for help with any problems! ---------------------------------------------------------------------------- Hi, I have a doubt about IPDuplicate event triggered by Network Sensor 6.0: Which IP is the duplicate one: source IP or destionation IP ? Why does RealSecure log two IPs (source/destionation) ? Thanks, Fernando
