RE: Spoof Attack

  • From: "Rami SIK" <rami@xxxxxxxxxxxxxxx>
  • To: "'[ISAserver.org Discussion List]'" <isalist@xxxxxxxxxxxxx>
  • Date: Mon, 9 Jun 2003 09:16:03 +0300

Hi Tom,

 

I further investigated the case, and realized that the spoofing packet is of
type ICMP 3. Then, I closed the inbound ICMP traffic on the Firewall located
before the ISA. I have not seen such alerts since then.

 

Thanks,

 

 

 

--------------------------------------------------------------------

Rami SIK

 

System & Network Administrator

CCNA

 

Kimyatas

Istanbul / Turkey

 

Tel:90-212-334 4963

--------------------------------------------------------------------

 

-----Original Message-----
From: Thomas W Shinder [mailto:tshinder@xxxxxxxxxxxxxxxxxx] 
Sent: Monday, June 09, 2003 4:29 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Spoof Attack

 

http://www.ISAserver.org

Hi Rami,

 

That explains the spoof. The address it was trying to contact was on the LAT
and LAT networks can never be connected to except through the ISA Server.

 

HTH,

Tom

Thomas W Shinder 
www.isaserver.org/shinder 
ISA Server and Beyond: http://tinyurl.com/1jq1 
Configuring ISA Server: http://tinyurl.com/1llp 

-----Original Message-----
From: Rami SIK [mailto:rami@xxxxxxxxxxxxxxx] 
Sent: Friday, June 06, 2003 1:50 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Spoof Attack

http://www.ISAserver.org

This is the following message I got:

 

ISA Server detected a spoof attack from Internet Protocol (IP) address
10.246.236.1. A spoof attack occurs when an IP address that is not reachable
via the interface on which the packet was received. If logging for dropped
packets is set, you can view details in the packet filter log.

 

 

My LAT table contains 10.0.0.0 - 10.255.255.255

 

My configuration is;

 

       |    10.x.x.x     |           |     192.168.2.x     |

LAN |---------------------|   ISA   |---------------------------|  Firewall

       |                     |           |                           |

 

 

--------------------------------------------------------------------

Rami SIK

 

System & Network Administrator

CCNA

 

Kimyatas

Istanbul / Turkey

 

Tel:90-212-334 4963

--------------------------------------------------------------------

 

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
rami@xxxxxxxxxxxxxxx
To unsubscribe send a blank email to $subst('Email.Unsub') 

Other related posts: