I lied...is not IP spoof...is 'Probable TCP FIN scan'. Does anyone know what that is?
Thanks, Debra -----Original Message----- From: debra Sent: 22 October 2001 08:45 To: 'Deon Grobler' Subject: RE: IPspoof in firewall logs Same here....two-three times a day Mon-Fri. -----Original Message----- From: Deon Grobler [mailto:[EMAIL PROTECTED]] Sent: 18 October 2001 18:44 To: [EMAIL PROTECTED] Subject: IPspoof in firewall logs Hiya guys I am getting this in my firewall logs which have been lasting for around 2 days now and can't seem to get anymore info on it. I am using a sonicwall firewall. Can anyone possibly help me find out how to solve this problem? 10/18/2001 11:53:18.240 - IP spoof detected - Source:10.2.0.4, 137, LAN - Destination:63.102.226.36, 137, WAN - MAC address: 00.B0.D0.F3.6F.4A - thanks Deon Grobler - Systems Engineer [EMAIL PROTECTED] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Bluewave USA Inc. - Online Creations http://www.bluewave.com/ Tel. +1 (212) 509 1520 x240 110 Wall Street, 10th Floor New York, NY 10005. USA ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~