08-21-2008 08:43 AM - edited 03-11-2019 06:34 AM
Hey guys,
Just checking my PIX logs and I keep getting this alert "Aug 21 2008 09:37:15: %PIX-2-106016: Deny IP spoof from (127.0.0.??) to 108.122.0.0 on interface dmz"
The last octet of the 127 address changes and it's to the same destination. Just wondering if this is a config issue on my end or is it a legit concern.
thanks,
08-21-2008 08:54 AM
Can you use the show arp command to determine the ethernet source address.
Regards.
08-21-2008 09:00 AM
There are no arp entries for the source or destination and there are no connections with those numbers either.
Still there it is.
08-21-2008 09:03 AM
What do you think about a capture?
08-21-2008 09:04 AM
What do you think about a capture?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide