Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

IP Spoofing

Status
Not open for further replies.

technical1

Technical User
Sep 2, 2002
52
GB
Good Morning All,
Ive noticed the following in my sys logs, could anyone shed some light on what they REALLY are, and whether my PIX has been compromised?

Output:
PIX-2-106016: Deny IP spoof from (127.0.0.1) to ip.ad.dr.ess on interface outside
PIX-2-106016: Deny IP spoof from (127.0.0.1) to ip.ad.dr.ess on interface outside

Regards,
Vinay
 
This message indicates that the packet has an invalid source address, in this case the loopback address 127.0.0.1 which is a reserved address. The PIX has not been compromised, but is indicating that its dropping these invalid packets.

I suspect that these packets are most likley to originate from an internal mis-configured host, as 127.0.0.0 addresses are supposed to be dropped by ISP routers. Therefore you should not see this address appear on the outisde interface.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top