Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chriss Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

IP Spoof received on Netscreen SSG20

Status
Not open for further replies.

350ztn

MIS
Nov 19, 2003
96
US
After installing a crossover cable between 2 servers. One Windows 2000 server and the other is Linux Suse9.3 and assiging a private IP address to the IP's the Windows server is sending spoof attacks and my firewall is picking them up. I've run antivirus, spybot and adware on the windows server with nothing malicious showing. Needing help to stop spoofing attacks. This only started to occur when the 2 servers were connected via crossover. The source in the attack info below is the Windows server and the port changes on it, the destination IP I have no idea who it is, but the IP and port are always the same. This spoofing occurs about every 25-30 minutes.

Attack info below
[00001] 2007-04-02 08:34:20 [Root]system-alert-00008: IP spoofing! From 192.168.254.5:1822 to 10.1.123.255:42508, proto UDP (zone Trust, int ethernet0/1). Occurred 1 times.

 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top