http://www.ISAserver.org ------------------------------------------------------- No doubt created by POS Devices, LLC? http://support.microsoft.com/kb/838114 NOTE - this is a GLOBAL change that disables IP spoofing for *ALL* networks. -----Original Message----- From: isalist-bounce@xxxxxxxxxxxxx [mailto:isalist-bounce@xxxxxxxxxxxxx] On Behalf Of William Holmes Sent: Tuesday, July 17, 2007 6:51 PM To: isalist@xxxxxxxxxxxxx Subject: [isalist] Re: ISA 2006 Anti-spoofing http://www.ISAserver.org ------------------------------------------------------- Hello, While I agree with you, It's is not possible to change the initial ipaddress that this device is using. Is it possible to turn off the anti-spoofing feature? Thanks -----Original Message----- From: isalist-bounce@xxxxxxxxxxxxx [mailto:isalist-bounce@xxxxxxxxxxxxx] On Behalf Of Jim Harrison Sent: Tuesday, July 17, 2007 9:42 PM To: isalist@xxxxxxxxxxxxx Subject: [isalist] Re: ISA 2006 Anti-spoofing http://www.ISAserver.org ------------------------------------------------------- "the source ip address its using is not within the range of the subnet its coming in from" - this is called IP spoofing. Better that you try to change the device behavior. -----Original Message----- From: isalist-bounce@xxxxxxxxxxxxx [mailto:isalist-bounce@xxxxxxxxxxxxx] On Behalf Of William Holmes Sent: Tuesday, July 17, 2007 4:24 PM To: isalist@xxxxxxxxxxxxx Subject: [isalist] ISA 2006 Anti-spoofing Hello, Is there a way to turn off anti-spoofing in ISA 2006? Here is the situation: I have my ISA server configured with several "internal" networks. I have the ISA server setup to do DHCP relaying for all the networks. I have another network device that is sending a DHCP request and the source ip address its using is not within the range of the subnet its coming in from. The destination address is the all ones broadcast address and the destination port is 67. However the ISA server is still rejecting the packet as spoofed. Ideally (at least I think it would be) the ISA server would ignore the source IP address of a DHCP request. The device is simply "trying" to get an appropriate ip address for the subnet it's connected to. I understand the benefits of anti-spoofing but I really want my DHCP relay to work for all my subnets. How do I go about shutting it off? Thanks Bill All mail to and from this domain is GFI-scanned. ------------------------------------------------------ List Archives: //www.freelists.org/archives/isalist/ ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server Articles and Tutorials: http://www.isaserver.org/articles_tutorials/ ISA Server Blogs: http://blogs.isaserver.org/ ------------------------------------------------------ Visit TechGenix.com for more information about our other sites: http://www.techgenix.com ------------------------------------------------------ To unsubscribe visit http://www.isaserver.org/pages/isalist.asp Report abuse to listadmin@xxxxxxxxxxxxx ------------------------------------------------------ List Archives: //www.freelists.org/archives/isalist/ ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server Articles and Tutorials: http://www.isaserver.org/articles_tutorials/ ISA Server Blogs: http://blogs.isaserver.org/ ------------------------------------------------------ Visit TechGenix.com for more information about our other sites: http://www.techgenix.com ------------------------------------------------------ To unsubscribe visit http://www.isaserver.org/pages/isalist.asp Report abuse to listadmin@xxxxxxxxxxxxx All mail to and from this domain is GFI-scanned. ------------------------------------------------------ List Archives: //www.freelists.org/archives/isalist/ ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp ISA Server Articles and Tutorials: http://www.isaserver.org/articles_tutorials/ ISA Server Blogs: http://blogs.isaserver.org/ ------------------------------------------------------ Visit TechGenix.com for more information about our other sites: http://www.techgenix.com ------------------------------------------------------ To unsubscribe visit http://www.isaserver.org/pages/isalist.asp Report abuse to listadmin@xxxxxxxxxxxxx