Deny IP spoof on Cisco ASA

Deny IP spoof on Cisco ASA

Secure Home | Search | About
 Networking Firewalls    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Deny IP spoof on Cisco ASA Chris 07-09-2007
Posted by Chris on July 9, 2007, 4:57 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi all,

Hopefully you can help with a problem I am having with Cisco syslog
message ASA-2-106016.

Basically we have a /27 public address range in our network and during
testing we are trying to prove that the access-lists on our firewall
is behaving as it should. The access-list allows through any traffic
from the /27 network on the inside interface and blocks any traffic
between the /27 network into the outside interface. Therefore if we
try to connect to ourselves the traffic should be stopped coming back
in on the outside interface.

What is actually happening is that one address is actually being
stopped from getting into the inside interface and the syslog message
is "Deny IP spoof from (our IP address) to (broadcast address of our
range) on interface inside". Addresses either side of the blocked
address work so we don't think it could be misconfiguration of mask.

Would anyone have an idea as to why this happens?

Many thanks,

Chris


Posted by Chris on July 9, 2007, 6:31 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> Hi all,
>
> Hopefully you can help with a problem I am having with Cisco syslog
> message ASA-2-106016.
>
> Basically we have a /27 public address range in our network and during
> testing we are trying to prove that the access-lists on our firewall
> is behaving as it should. The access-list allows through any traffic
> from the /27 network on the inside interface and blocks any traffic
> between the /27 network into the outside interface. Therefore if we
> try to connect to ourselves the traffic should be stopped coming back
> in on the outside interface.
>
> What is actually happening is that one address is actually being
> stopped from getting into the inside interface and the syslog message
> is "Deny IP spoof from (our IP address) to (broadcast address of our
> range) on interface inside". Addresses either side of the blocked
> address work so we don't think it could be misconfiguration of mask.
>
> Would anyone have an idea as to why this happens?
>
> Many thanks,
>
> Chris

D'oh! Case now closed. Despite me saying that there wasn't misconfig
it turns out that the management IP address was configured with the
wrong mask.


Similar ThreadsPosted
Spoof Protection With Firewall-1 August 27, 2006, 1:13 am
106023: Deny tcp src outside from WWW Servers September 7, 2005, 5:04 am
checkpoint firewall default deny? February 15, 2005, 9:00 pm
Zone Alarm - allow deny - remember this setting....? June 13, 2005, 4:52 am
Deny TCP (no connection) flags RST on inside intf ? PIX 6.3.5 April 14, 2006, 12:53 pm
PIX firewall floods with PIX-4-106023: Deny tcp src inside message. May 10, 2006, 2:35 am
Enterasys Secure Router XSR3150 "Deny Massage" December 7, 2006, 8:46 pm
Cisco pix 515+ static routes between 2 cisco pix October 13, 2005, 8:09 pm
Cisco pix 515 + static routes between 2 cisco pix October 13, 2005, 8:12 pm
WTB: CISCO WE ARE BUYING USED CISCO EQUIPMENT. February 14, 2008, 8:14 am

The site map in XML format XML site map

Contact Us | Privacy Policy