<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic spoof log in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/spoof-log/m-p/1498083#M689822</link>
    <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am getting this log message from ASA5520 :&lt;/P&gt;&lt;P&gt;Deny IP spoof from (Cicso_Works) to 10.162.50.70 on interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notes:&lt;/P&gt;&lt;P&gt;-cisco_works is in inside interface&lt;/P&gt;&lt;P&gt;-10.162.50.70 is the IP of one interface (one DMZ) in ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i can't understand why am i getting this message!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 17:47:46 GMT</pubDate>
    <dc:creator>ohassairi</dc:creator>
    <dc:date>2019-03-11T17:47:46Z</dc:date>
    <item>
      <title>spoof log</title>
      <link>https://community.cisco.com/t5/network-security/spoof-log/m-p/1498083#M689822</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am getting this log message from ASA5520 :&lt;/P&gt;&lt;P&gt;Deny IP spoof from (Cicso_Works) to 10.162.50.70 on interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Notes:&lt;/P&gt;&lt;P&gt;-cisco_works is in inside interface&lt;/P&gt;&lt;P&gt;-10.162.50.70 is the IP of one interface (one DMZ) in ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i can't understand why am i getting this message!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:47:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spoof-log/m-p/1498083#M689822</guid>
      <dc:creator>ohassairi</dc:creator>
      <dc:date>2019-03-11T17:47:46Z</dc:date>
    </item>
    <item>
      <title>Re: spoof log</title>
      <link>https://community.cisco.com/t5/network-security/spoof-log/m-p/1498084#M689823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since 10.162.50.70 is supposed to be connected to &lt;STRONG&gt;DMZ&lt;/STRONG&gt; interface as advised, and you are actually getting the traffic on &lt;STRONG&gt;inside &lt;/STRONG&gt;interface of the ASA, that is why you are getting the spoof error message. Traffic sourced from 10.162.50.70 should only go inbound towards the ASA DMZ interface, not any other interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that answers your question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 May 2010 08:40:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spoof-log/m-p/1498084#M689823</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-19T08:40:55Z</dc:date>
    </item>
    <item>
      <title>Re: spoof log</title>
      <link>https://community.cisco.com/t5/network-security/spoof-log/m-p/1498085#M689824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you said:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1-Since 10.162.50.70 is supposed to be connected to &lt;STRONG&gt;DMZ&lt;/STRONG&gt; interface&lt;/P&gt;&lt;P&gt;-&amp;gt;actually this IP is the IP of the DMZ interface itself and not of one PC connected to DMZ &lt;/P&gt;&lt;P&gt;2-Traffic sourced from 10.162.50.70 should only go inbound towards the ASA DMZ interface,&lt;/P&gt;&lt;P&gt;-&amp;gt; according to the syslog msg, the traffic is sourced from cisco_works and not 10.162.50.70!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i can't understand your explanaition &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 May 2010 04:31:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spoof-log/m-p/1498085#M689824</guid>
      <dc:creator>ohassairi</dc:creator>
      <dc:date>2010-05-20T04:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: spoof log</title>
      <link>https://community.cisco.com/t5/network-security/spoof-log/m-p/1498086#M689825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems that there might be some routing loop that is causing packet that is sourced from the ASA DMZ interface to arrive on the inside interface instead.&lt;/P&gt;&lt;P&gt;Most times it is caused by routing loop in your network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 May 2010 07:51:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/spoof-log/m-p/1498086#M689825</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-20T07:51:57Z</dc:date>
    </item>
  </channel>
</rss>

