cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
251
Views
0
Helpful
1
Replies

MARS and FWSM NAT translation

hoffa2000
Level 3
Level 3

Greetings

I've been running CS-MARS along with an FWSM and IDSM for about a year now and has always wanted to know one thing.

If the IDSM send an alert originating from the FWSM global IP I 'sometimes' get a translation into the internal NATed IP address. It's about a 10% success ratio.

All systems are set with NTP to an internal server and I see no special pattern to it.

Any ideas?

Best regards

Fredrik

1 Reply 1

tstanik
Level 5
Level 5

You need to check the NAT rules to find out which rule is working and changing the IP. After this scan the network traffic and determine at which particular traffic this happens.