Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

How to Prevent ip spoof attack on isa

Status
Not open for further replies.

ocnu

IS-IT--Management
Nov 23, 2001
1
TT
Event Type: Warning
Event Source: Microsoft ISA Server Control
Event Category: Packet filter
Event ID: 15108
Date:
Time:
User: N/A
Computer: computerX
Description:
ISA Server detected a spoof attack from Internet Protocol (IP) address **.***.***.**. A spoof attack occurs when an IP address that is not reachable via the interface on which the packet was received. If logging for dropped packets is set, you can view details in the packet filter log.
Data:
0000: 1f 00 00 00 ....
 
I don't quite understand you question. This ISA server did prevent the spoof attack by filtering the packet. Do you want to disable Spoof Filtering?

Joe
 
You cannot per say prevent ip spoof attacks. The method an intruder wishes to use are up to him/her and not to ISA. By your message shown, your ISA is configured to detect such attacks and block them. If you wish to further harden your ISA server, is an excellent place for helpful how-to's.



Claudius (What certifications??)
 
You make a very good point. I chose my words poorly:-(. You are exactly right in what ISA does when a spoof attack occurs.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top