cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7327
Views
3
Helpful
5
Replies

106016: Deny IP Spoof Error on ASA 5510

pjscott13
Level 1
Level 1

Hi All,

I am receiving a number of errors on my Cisco ASA 5510 device that reads:

106016: Deny IP spoof from (127.0.0.1) to x.x.x.x on Interface Inside

x.x.x.x is some random IP Address. There are a number of IP Addresses that are reported.

Any ideas?

5 Replies 5

Farrukh Haroon
VIP Alumni
VIP Alumni

Since that is a loopback IP, it could be any host. Probably one with vmware etc. Do a packet capture for that IP and get the mac-address. Then trace it on your network

Regards

Farrukh

I have to admit that the x.x.x.x ip addresses that appear are external public IP addresses that I have no idea what they are.

Also on the Internal Interface of the ASA there is an ISA Server... there is nothing between the ASA and ISA server. Is there another way of getting a packet capture without installing a hub between the ASA and the ISA... as obviously this means there will be an outage while I install the hub?

Well there is a capture command built-in the ASA:

http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807c35e7.shtml#s3

Once you get the mac-address, wireshark will show you the vendor name as derived from the MAC Address OID field (or you can google it up pretty quick).

Regards

Farrukh

Thanks! This is somewhat helpful. From what I have found the MAC address is of the ISA server (which is the only thing that connects to the Inside interface of the ASA... no surprise really) but why?

The packet capture shows that the source IP Address is 127.0.0.1 with the MAC of the ISA server and the Destination is of various external IP Addresses with the destination MAC address of the ASA.

What can I check now?

I would run a whois on those external IPs to see what they are really, this might give you an idea about the traffic. What is the destination port? (If its TCP/UDP) traffic?

Download process explorer and run it on your ISA server (no need to install it,its standalone).

http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx

Check which 'service' or application is opening these connections from the ISA server. Perhaps a trojan/worm...

Regards

Farrukh

Review Cisco Networking for a $25 gift card