<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deny ip Spoof in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/deny-ip-spoof/m-p/685001#M1031134</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello reto,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the source of the spoof attack coming from ?? if it is one of these, then the PIX blocks all the spoof traffic by default, since thats the way it is supposed to work:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) 127.0.0.1 - loopback&lt;/P&gt;&lt;P&gt;2) broadcast address&lt;/P&gt;&lt;P&gt;3) land.c subnets - your same network...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is something else, we have to analyse what IP is that and see if it is required.. Are you not able to connect to the PIX outside at all from the internet ?? this should not be the case.. can you do a tracert and find out where it is dropping ?? Are there any other log messages on the PIX ?? Try going to internet through a laptop.. take the IP of that laptop and connect to PIX. see if there are any packets hitting the firewall with that laptop's IP ... am sure you can nail down the issue...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.. let us know..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 Jan 2007 06:07:40 GMT</pubDate>
    <dc:creator>sachinraja</dc:creator>
    <dc:date>2007-01-26T06:07:40Z</dc:date>
    <item>
      <title>Deny ip Spoof</title>
      <link>https://community.cisco.com/t5/network-security/deny-ip-spoof/m-p/685000#M1031080</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm using an ASA5510. I want enable VPN-Client Access, but there is always the Message: "Deny ip Spoof from (..) on Interface outside". I'm also not able to ping this device. ACL's are open and the command:&lt;/P&gt;&lt;P&gt;icmp permit any unreachable outside&lt;/P&gt;&lt;P&gt;icmp permit any outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could someone give me a solution?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:24:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ip-spoof/m-p/685000#M1031080</guid>
      <dc:creator>reto.rutishauser</dc:creator>
      <dc:date>2019-03-11T09:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: Deny ip Spoof</title>
      <link>https://community.cisco.com/t5/network-security/deny-ip-spoof/m-p/685001#M1031134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello reto,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the source of the spoof attack coming from ?? if it is one of these, then the PIX blocks all the spoof traffic by default, since thats the way it is supposed to work:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) 127.0.0.1 - loopback&lt;/P&gt;&lt;P&gt;2) broadcast address&lt;/P&gt;&lt;P&gt;3) land.c subnets - your same network...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is something else, we have to analyse what IP is that and see if it is required.. Are you not able to connect to the PIX outside at all from the internet ?? this should not be the case.. can you do a tracert and find out where it is dropping ?? Are there any other log messages on the PIX ?? Try going to internet through a laptop.. take the IP of that laptop and connect to PIX. see if there are any packets hitting the firewall with that laptop's IP ... am sure you can nail down the issue...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.. let us know..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Jan 2007 06:07:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ip-spoof/m-p/685001#M1031134</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2007-01-26T06:07:40Z</dc:date>
    </item>
  </channel>
</rss>

