Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Spoofing Packets Dropped

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2004 Firewall] >> SecureNAT Client >> Spoofing Packets Dropped Page: [1]
Login
Message << Older Topic   Newer Topic >>
Spoofing Packets Dropped - 30.Aug.2006 1:27:04 PM   
dantheman

 

Posts: 28
Joined: 29.May2006
Status: offline
Hi,
I have a problem with allowing traffic from UNIX telephone servers. this is the situation

UNIXTelServer1 10.125.8.1 has had routes applied to it to pass traffic to our ISA servers via routes defined on our CISCO routers

The ISA servers are on a  different subnet 10.30.x.x and have a route defined to route any 10.x.x.x traffic to its internal NIC, then its default GW is the DMZ router 192.168.x.x, this is then NAT'd out to the internet by the Router to, for example 89.20.20.x

So the isa box has 1 internal interface 10.30.9.70 and an external interface 192.168.x.3


However, ISA is dropping the packets as spoofed. When i look at the log, i see this

Client IP                 Dest IP                Dest Port                 Action                                  Result Code
10.125.8.1              216.191.234.x       443                        Allowed Connection                 0x0
89.20.20.3              216.191.234.x       443                        Denied Connection                  FWX_E_FWE_SPOOFING_PACKET_DROPPED

This seems to me really odd, as it is showing a connection from the Nat's 89.x.x.x to the internet, but how would ISA even know what it's external Nat'd addresses are. Normally it will show the connection from 192.168.x.3 for connections.

Can anyone help me with why ISA is behaving like this, or could it be to do with the CISCO routing??

Thanks,

Post #: 1

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2004 Firewall] >> SecureNAT Client >> Spoofing Packets Dropped Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts