RE: ISA Event id 15108 & 14120

  • From: mathif@xxxxxxxxxxxxxxx
  • To: isalist@xxxxxxxxxxxxx
  • Date: Wed, 14 Apr 2004 12:22:43 +0300

Hi All,
Finally I was able to solve this problem. Both this events were due to
mismatch in routing table and LAT. Actually, I was accessing this Server
from a terminal which is in different subnet. Actually I manually created a
routing entry for this on ISA server and didn't add that to LAT. Finally
when I added this entry to LAT it worked and all the 2 events disappeared..

FYI,
Athif

>  -----Original Message-----
> From:         Mohammed Athif Khaleel  
> Sent: Monday, 12 April 2004 5:04 PM
> To:   'isalist@xxxxxxxxxxxxx'
> Subject:      RE: ISA Event id 15108 & 14120
> 
> 
>       Hi All,
> 
>       I am getting this error Event id 15108 & 14120on the Windows 2000
> ISA SERVER, SP1,FP1, Integrated Mode with 2 NIC
> 
>       "ISA Server detected a spoof attack from Internet Protocol (IP)
> address 212.100.193.18. A spoof attack occurs when an IP address that is
> not reachable via the interface on which the packet was received. If
> logging for dropped packets is set, you can view details in the packet
> filter log. "
> 
>       Also,  Event id 14120 "The ISA Server services cannot create a
> packet filter 212.100.193.18. This event occurs when there is a conflict
> between the Local Address Table (LAT) configuration and the Windows 2000
> routing table. Check the routing table and the LAT to find the source of
> the conflict. "
> 
>       I have checked the LAT, external interface and upstream IP is not
> included in LAT. 
> 
>       How do I overcome this? Internet is damn slow on this.
> 
>       Any thoughts please.
> 
>       Thanks,
>       Athif
> 
> 
  ----------------------------------------------------- 
 This email and any files transmitted with it are confidential and intended
solely for the use of the individual or entity to whom/which they are
addressed. If you have received this email in error please notify the system
manager at the following email address: sadmin@xxxxxxxxxxxxxxx
<mailto:sadmin@xxxxxxxxxxxxxxx>. Please note that any views or opinions
presented in this email are solely those of the author and do not
necessarily represent those of Al Faisaliah Group. Internet communications
cannot be guaranteed to be secure or error-free as information could be
intercepted, corrupted, lost, arrive late or contain viruses. The sender
therefore does not accept liability for any errors or omissions in the
context of this message, which arise as a result of Internet transmission.
Finally, the recipient should check this email and any attachments for the
presence of viruses. Al Faisaliah Group accepts no liability for any damage
caused by any virus transmitted by this email. 
  ----------------------------------------------------- 
 

Other related posts: