<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Deny IP spoof from (127.0.0.1) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/deny-ip-spoof-from-127-0-0-1/m-p/1480710#M726895</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you both for the answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i figured for sure it was coming form the outside but like i said, the debug wasn't very helpful when i was looking at it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'll setup a mirror port on my stack for the outside and see if i can catch it. thanks again, you've given me a great staring point.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 May 2010 14:22:42 GMT</pubDate>
    <dc:creator>sysadmin</dc:creator>
    <dc:date>2010-05-04T14:22:42Z</dc:date>
    <item>
      <title>Deny IP spoof from (127.0.0.1)</title>
      <link>https://community.cisco.com/t5/network-security/deny-ip-spoof-from-127-0-0-1/m-p/1480707#M726892</link>
      <description>&lt;P&gt;Greetings!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have recently began to receive these errors on my ASA 5510. I've done a debug when it occurs but haven't noticed an unusual traffic coming from the internal or external network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here's the error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2|May 03 2010|12:04:08|106016|||||Deny IP spoof from (127.0.0.1) to OUR_EXT_IP on interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;based on the message. should I be looking on the inside or outside of my fw? This is really the first time i've seen these messages so i'm sorta green to them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you need more logs, let me know and i can provide here. thanks for the help!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:40:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ip-spoof-from-127-0-0-1/m-p/1480707#M726892</guid>
      <dc:creator>sysadmin</dc:creator>
      <dc:date>2019-03-11T17:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: Deny IP spoof from (127.0.0.1)</title>
      <link>https://community.cisco.com/t5/network-security/deny-ip-spoof-from-127-0-0-1/m-p/1480708#M726893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is what syslog# 106016 means for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4768961"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4768961&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the traffic is coming from the outside interface/external to your network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 May 2010 03:19:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ip-spoof-from-127-0-0-1/m-p/1480708#M726893</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-04T03:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Deny IP spoof from (127.0.0.1)</title>
      <link>https://community.cisco.com/t5/network-security/deny-ip-spoof-from-127-0-0-1/m-p/1480709#M726894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;It could be a virus attack or it could be that someone is trying to compromise the network by sending traffic using a soofed ip address. The best way would be take sniffer so that you could see the MAC address of the faulty machine/source.&lt;/P&gt;&lt;P&gt;Also, if you want to disable this log message, you can do that as well, as follows:&lt;/P&gt;&lt;P&gt;no logging message 106016&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;HTH&lt;/P&gt;&lt;P&gt;Ashu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 May 2010 12:47:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ip-spoof-from-127-0-0-1/m-p/1480709#M726894</guid>
      <dc:creator>astripat</dc:creator>
      <dc:date>2010-05-04T12:47:59Z</dc:date>
    </item>
    <item>
      <title>Re: Deny IP spoof from (127.0.0.1)</title>
      <link>https://community.cisco.com/t5/network-security/deny-ip-spoof-from-127-0-0-1/m-p/1480710#M726895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you both for the answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i figured for sure it was coming form the outside but like i said, the debug wasn't very helpful when i was looking at it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i'll setup a mirror port on my stack for the outside and see if i can catch it. thanks again, you've given me a great staring point.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 May 2010 14:22:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/deny-ip-spoof-from-127-0-0-1/m-p/1480710#M726895</guid>
      <dc:creator>sysadmin</dc:creator>
      <dc:date>2010-05-04T14:22:42Z</dc:date>
    </item>
  </channel>
</rss>

