All,

      We've seen a small amount of activity that looks like a PC might be
spoofing and IP of 0.0.0.0. My desire is to setup our sensors to log those
packets in hopes of revealing the MAC address that they are originating
from. I have the firewall filter setup in our ProventiaG for that but I'm
not sure how to accomplish this on the Proventia_A201 devices. I need to
get them all to log/capture these packets because I want to track this down
before I have the network team implement anti-spoofing filters on all the
router interfaces.

      It would be nice if there was a signature for spoofed addresses. If
there is I have missed it but there's no good way to search through all the
XPUs and the search feature seemed to break as it stops on the first match.
There needs to be a "find next" because unless I know the exact name of a
signature it doesn't help.

Regards,
Chris Norris CISSP

_______________________________________________
ISSForum mailing list
[email protected]

TO UNSUBSCRIBE OR CHANGE YOUR SUBSCRIPTION, go to 
https://atla-mm1.iss.net/mailman/listinfo/issforum

To contact the ISSForum Moderator, send email to [EMAIL PROTECTED]

The ISSForum mailing list is hosted and managed by Internet Security Systems, 
6303 Barfield Road, Atlanta, Georgia, USA 30328.

Reply via email to