Welcome to ISAserver.org
Forums |
Register |
Login |
My Profile |
Inbox |
RSS
|
My Subscription |
My Forums |
Address Book |
Member List |
Search |
FAQ |
Ticket List |
Log Out
Spoofing Packets Dropped
|
Users viewing this topic:
none
|
Logged in as: Guest
|
Login | |
|
Spoofing Packets Dropped - 30.Aug.2006 1:27:04 PM
|
|
|
dantheman
Posts: 28
Joined: 29.May2006
Status: offline
|
Hi, I have a problem with allowing traffic from UNIX telephone servers. this is the situation UNIXTelServer1 10.125.8.1 has had routes applied to it to pass traffic to our ISA servers via routes defined on our CISCO routers The ISA servers are on a different subnet 10.30.x.x and have a route defined to route any 10.x.x.x traffic to its internal NIC, then its default GW is the DMZ router 192.168.x.x, this is then NAT'd out to the internet by the Router to, for example 89.20.20.x So the isa box has 1 internal interface 10.30.9.70 and an external interface 192.168.x.3 However, ISA is dropping the packets as spoofed. When i look at the log, i see this Client IP Dest IP Dest Port Action Result Code 10.125.8.1 216.191.234.x 443 Allowed Connection 0x0 89.20.20.3 216.191.234.x 443 Denied Connection FWX_E_FWE_SPOOFING_PACKET_DROPPED This seems to me really odd, as it is showing a connection from the Nat's 89.x.x.x to the internet, but how would ISA even know what it's external Nat'd addresses are. Normally it will show the connection from 192.168.x.3 for connections. Can anyone help me with why ISA is behaving like this, or could it be to do with the CISCO routing?? Thanks,
|
|
|
|
New Messages |
No New Messages |
Hot Topic w/ New Messages |
Hot Topic w/o New Messages |
Locked w/ New Messages |
Locked w/o New Messages |
|
Post New Thread
Reply to Message
Post New Poll
Submit Vote
Delete My Own Post
Delete My Own Thread
Rate Posts |
|