cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1193
Views
0
Helpful
2
Replies

I am getting this error in PIX syslog...

plemieux72
Level 1
Level 1

2002-05-12 18:03:44 Local4.Critical 192.168.1.1 %PIX-2-106017: Deny IP due to Land Attack from 10.1.1.10 to 10.1.1.10

What might be causing this?

2 Replies 2

johnbroadway
Level 1
Level 1

I took this from:

http://www.cisco.com/univercd/cc/td/doc/product/iaabu/pix/pix_v53/syslog/pixemapa.htm

%PIX-2-106017: Deny IP due to Land Attack from IP_addr to IP_addr

Explanation This message appears when PIX Firewall receives a packet with the IP source address equal to the IP destination and the destination port equal to the source port. This indicates a spoofed packet designed to attack systems. This attack is referred to as a Land Attack.

Action If this message persists, an attack may be in progress. The packet does not provide enough information to determine where the attack originates

I thought that was strange because 10.1.1.10 is part of my VPN pool and I was not sure if I had configured the PIX correctly. Thanks!

Review Cisco Networking for a $25 gift card