Seems like a spoofing attempt, unless this address is used by your internal hosts/ VPN clients/ or WAN links of routers.
Does it match any of this?
Where is interface "ext" connected to? Is it to the ISP or some other organization?
Post here the whole line of the syslog message.
Anyway it is normal that your pix is been attacked from the Internet mostly with port scans, if the logs are empty it might meen that the Internet connection is down...
But it is good that you track the logs to find abnormal activitiy - and if 10.0.1.1 is a legitimat address in your network - for example VPN client or partner connected to your network, it is something to be more worried about.
The ext interface is connected to a stand alone switch where the ISP router also is connected. On this switch i also have different other networks connected. None of them are the IP-scope specified. They use another 10.X.X.X address.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.