• RSS
  • Twitter
  • FaceBook

Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

Error 15108 Spoof Attack

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA Server 2000 General] >> General >> Error 15108 Spoof Attack Page: [1]
Login
Message << Older Topic   Newer Topic >>
Error 15108 Spoof Attack - 24.Sep.2002 9:20:00 PM   
asimmoin

 

Posts: 1
Joined: 24.Sep.2002
Status: offline
I'm running a tri-homed isa firewall and the firewall keeps on getting these spoof attacks. The main thing is that my firewall is in a secured network, i mean its not exposed to the internet and as soon as the warnings frequency increases the firewall freezes. If anyone has any solutions or suggestions please reply. Thank you.

Event Type: Warning
Event Source: Microsoft ISA Server Control
Event Category: Packet filter
Event ID: 15108
Date: 7/5/2002
Time: 9:17:49 AM
User: N/A
Computer: NJBH1
Description:
ISA Server detected a spoof attack from Internet Protocol (IP) address 169.224.10.26. A spoof attack occurs when an IP address that is not reachable via the interface on which the packet was received. If logging for dropped packets is set, you can view details in the packet filter log.
Data:
0000: 1f 00 00 00 ....
Post #: 1
RE: Error 15108 Spoof Attack - 28.Oct.2002 9:21:00 AM   
sir_aelurus

 

Posts: 10
Joined: 16.Oct.2002
From: New Zealand
Status: offline
I am experiencing the same problem, if anyone has a solution or even a suggestion, please post it!

(in reply to asimmoin)
Post #: 2
RE: Error 15108 Spoof Attack - 28.Oct.2002 4:54:00 PM   
AlexS

 

Posts: 155
Joined: 4.Feb.2002
Status: offline
Likely a problem with misconfigured LAT and/or bad configuration of other components (check RRAS, for example - the address looks like*** "automatic" IP address which is assigned when RAS configured to use DHCP but no DHCP servers are available). Trace to that IP to find out which interface is "correct one" for that destination.

*** It should be 169.254.x.x - "Automatic Private IP Addressing" (APIPA) - you were mentioning 169. 224

(in reply to asimmoin)
Post #: 3
RE: Error 15108 Spoof Attack - 28.Oct.2002 7:54:00 PM   
tshinder

 

Posts: 50013
Joined: 10.Jan.2001
From: Texas
Status: offline
Hey guys,

I agree, looks like a LAT configuration issue.

HTH,
Tom

(in reply to asimmoin)
Post #: 4
RE: Error 15108 Spoof Attack - 28.Jan.2003 5:56:00 PM   
massive

 

Posts: 8
Joined: 26.Oct.2002
From: Netherlands
Status: offline
I have this same problem, many many times a week. I checked my own LAT ofcourse and routing table.

Here's the situation:
- my internal address 192.168.2.xxx
- my modem 10.0.0.138
- my modem nic 10.0.0.151
- internal address range from neighbour (with wireless lan connection) 192.168.1.xxx
- there's a extra route in the w2k routing table on the isa server, which leads all 192.168.1.0 trafic, to the gateway on his network. (that works fine)

The lat entries in ISA are simple: just 192.168.1.0 and 192.168.2.0

The modem nic is made an external ip this way (I think) so the routing is easier.

Every incoming connection on the modem will be forwarded to the modem nic (10.0.0.151).

Is there something wrong here ???

Please Reply !

(in reply to asimmoin)
Post #: 5
RE: Error 15108 Spoof Attack - 28.Jan.2003 11:19:00 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Massive,

the LAT should contain *all* your internal IP's, nothing more, nothing less. With the given information the LAT should contain 192.168.1.0 - 192.168.2.255.

HTH,
Stefaan

(in reply to asimmoin)
Post #: 6
RE: Error 15108 Spoof Attack - 30.Jan.2003 10:52:00 AM   
massive

 

Posts: 8
Joined: 26.Oct.2002
From: Netherlands
Status: offline
well, that's what I thought spouse-eele. Then it really must be a spoofattack. I have this about once a week or something !

(in reply to asimmoin)
Post #: 7
RE: Error 15108 Spoof Attack - 30.Jan.2003 11:05:00 PM   
spouseele

 

Posts: 12830
Joined: 1.Jun.2001
From: Belgium
Status: offline
Hi Massive,

which IP addresses are reported in those attacks? Also, you might check out the IP packet filter logs for more details about the packets causing this alerts. Just make sure you set ISA to log all fields.

HTH,
Stefaan

(in reply to asimmoin)
Post #: 8
RE: Error 15108 Spoof Attack - 30.Jan.2003 11:55:00 PM   
Guest
I had similar problem. I still have it now, but not as bad any more. Spoof attacks were coming from 3 of my internal addresses, because of that Internet connection was locking down, actualy what it was, my NICs were disable for some time, ISA thought that it's real spoof attack. What it turnd out to be was Adaptec Storage Manager Pro was installed on all 3 of those machines and configured to be a master, all three computers were constantly broadcasting, creating those spoof attacks. I had to uninstall all of my Adaptec Storage Managers and reinstalling it with only ONE master. I still get the spoof attack from the master machine IP, but my connection is stable. I have a lot on my plate at the moment, so I'll worry about it later. If I find solution to this, I will let you know.

Lidiya

(in reply to asimmoin)
  Post #: 9
RE: Error 15108 Spoof Attack - 31.Mar.2004 6:37:00 AM   
vhunter

 

Posts: 8
Joined: 27.Nov.2003
From: Vn
Status: offline
though I reconstruct the LAT but the problem still remain

(in reply to asimmoin)
Post #: 10
RE: Error 15108 Spoof Attack - 31.Mar.2004 7:59:00 AM   
vhunter

 

Posts: 8
Joined: 27.Nov.2003
From: Vn
Status: offline
and the problem just happen if I create a Packet Filter that allow the ISA server to connect to the Internet, what should I have to do now

(in reply to asimmoin)
Post #: 11
RE: Error 15108 Spoof Attack - 5.Apr.2004 8:14:00 AM   
vhunter

 

Posts: 8
Joined: 27.Nov.2003
From: Vn
Status: offline
this is what I got when searching for help in google, it's from microsoft and now I have a litle experiance about this but still not solve the problem, any idea?? [Confused]

quote:

FIX: Cannot Renew DHCP Assigned IP Address on External ISA Interface
View products that this article applies to.
This article was previously published under Q326116
SYMPTOMS
On a computer running Internet Security and Acceleration Server, where the external interface is configured to have its IP address dynamically assigned from DHCP, you may not be able to renew the IP address on the interface.

For example, if you run ipconfig /release, followed by ipconfig /renew, from a command prompt, you may receive an error message similar to the following:

The following error occurred when renewing adapter MyAdapterName: DHCP Server unreachable
Additionally, you may not be able to turn off and turn on the external network adapter, or to automatically or manually change the assigned IP address on the external network adapter in ISA Server.

This problem also occurs when you have the DHCP Client Static Packet filter turned on in ISA Server.

The only way to renew the IP address is to temporarily turn off packet filtering or restart the computer running ISA Server.
CAUSE
The DHCP Client Static Packet filter only permits you to refresh the already assigned external IP address.

For example, when the DHCP lease has expired and the IP address on the external interface is lost or manually released, a renew of the IP address is blocked by the ISA Server Packet Filter module. The ISA service is not fully Plug and Play when the IP address is released on the external interface. Therefore, packet filtering is still applied to the interface.
RESOLUTION
You must install ISA Server Service Pack 1 (SP1) before you install the following hotfix. For additional information about how to obtain the latest ISA Server service pack, click the article number below to view the article in the Microsoft Knowledge Base:
313139 How to Obtain the Latest Internet Security and Acceleration Server 2000 Service Pack

A supported fix is now available from Microsoft, but it is only intended to correct the problem that is described in this article. Apply it only to computers that are experiencing this specific problem. This fix may receive additional testing. Therefore, if you are not severely affected by this problem, Microsoft recommends that you wait for the next Internet Security and Acceleration Server 2000 service pack that contains this fix.

To resolve this problem immediately, contact Microsoft Product Support Services to obtain the fix. For a complete list of Microsoft Product Support Services phone numbers and information about support costs, visit the following Microsoft Web site:
http://support.microsoft.com/default.aspx?scid=fh;EN-US;CNTACTMS

NOTE: In special cases, charges that are ordinarily incurred for support calls may be canceled if a Microsoft Support Professional determines that a specific update will resolve your problem. The typical support costs will apply to additional support questions and issues that do not qualify for the specific update in question.

To install the fix, run the self-extracting file. You do not have to restart the ISA Server computer. If the computer is part of an ISA Server array, you do not have to shut down the whole array. You can still install this fix on a one-by-one basis.

The English version of this fix has the file attributes (or later) that are listed in the following table. The dates and times for these files are listed in coordinated universal time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel. Date Time Version Size File name
--------------------------------------------------------
24-Oct-2002 20:21 3.0.1200.179 176,912 Mspadmin.exe
24-Oct-2002 20:20 3.0.1200.179 388,368 W3proxy.exe
24-Oct-2002 20:21 3.0.1200.179 297,232 Wspsrv.exe
24-Oct-2002 20:21 3.0.1200.179 99,600 Msphlpr.dll

This fix also applies to the French, German, Spanish, and Japanese versions of ISA Server.

STATUS
Microsoft has confirmed that this is a problem in the Microsoft products that are listed at the beginning of this article.
MORE INFORMATION
Note that after you install this hotfix, while you are renewing the DHCP assigned IP address, you may receive an event notice in the Application Event Log similar to the following:

Event Type: Warning
Event Source: Microsoft Firewall
Event ID: 14223
Description:
The description for Event ID (14223) in Source (Microsoft Firewall) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer.
The following information is part of the event:

This event may be logged if some of the packet filters could not be restored when the interface is re-created by using the new IP address. As a result, some active connections may be dropped during the renewal process.
When you release the DHCP assigned IP address, you may also receive an event message similar to the following:

Event Type: Warning
Event Source: Microsoft ISA Server Control
Event Category: Packet filter
Event ID: 15108
Description:
ISA Server detected a spoof attack from Internet Protocol (IP) address 10.10.10.10. A spoof attack occurs when an IP address that is not reachable via the interface on which the packet was received. If logging for dropped packets is set, you can view details in the packet filter log.
For example, this event may appear in the log if the packet filter is currently handling a packet. While you change the IP address on the external adapter, this causes routing table changes in the operating system (OS). Because ISA Server does spoof detection by comparing the interface on which the packet was received to the interface from which a reply to the originating source would be sent, it would consider this to be a spoofed packet if the two interfaces are different.

The following is still not supported after you install this hotfix:
If you change the IP address on the internal network adapter, SecureNAT stops functioning.

NOTE: Such changes are rare because in a SecureNAT scenario, the internal IP address of the ISA Server computer should never use DHCP, which must be configured as a gateway on the router or on all computers in the local internal subnet.
Dynamic filters for listeners that bind to IP 0.0.0.0 are not opened in the following scenarios:
A new external IP is added after the filters for the listener were created.
An external network adapter that is not a Routing and Remote Access service demand-dial (that existed when dynamic filters for the listener were created) is turned off, and receives a new IP when it is turned on. The only ISA application filter that opens the listener is the H.323 filter, which opens TCP port 1720 for incoming calls.
Local Address Table (LAT) changes that change the status of a network adapter from external to internal, or from internal to external, are not supported. In this case, ISA Management also prompts you to restart the ISA services.
The information in this article applies to:
Microsoft Internet Security and Acceleration Server 2000
Microsoft Internet Security and Acceleration Server 2000 SP1
Last Reviewed: 11/9/2002 (2.0)
Keywords: kbbug kberrmsg kbISAServ2000preSP2fix kbQFE KB326116



(in reply to asimmoin)
Post #: 12
RE: Error 15108 Spoof Attack - 22.Apr.2004 5:06:00 PM   
Guest
I also had the spoofing problem for about 3 weeks. I was reading a related article and it mentioned that Win2000 only likes 1 gateway. I had a different gateway on both the internal and external NIC. I deleted the one on my internal NIC and used a static entry instead. Spoofing entries cleared up in a couple of days.

quote:
Originally posted by asim:
I'm running a tri-homed isa firewall and the firewall keeps on getting these spoof attacks. The main thing is that my firewall is in a secured network, i mean its not exposed to the internet and as soon as the warnings frequency increases the firewall freezes. If anyone has any solutions or suggestions please reply. Thank you.

Event Type: Warning
Event Source: Microsoft ISA Server Control
Event Category: Packet filter
Event ID: 15108
Date: 7/5/2002
Time: 9:17:49 AM
User: N/A
Computer: NJBH1
Description:
ISA Server detected a spoof attack from Internet Protocol (IP) address 169.224.10.26. A spoof attack occurs when an IP address that is not reachable via the interface on which the packet was received. If logging for dropped packets is set, you can view details in the packet filter log.
Data:
0000: 1f 00 00 00 ....


(in reply to asimmoin)
  Post #: 13
RE: Error 15108 Spoof Attack - 20.Dec.2004 5:36:00 PM   
mgqa

 

Posts: 2
Joined: 30.Dec.2003
From: Austin, Tx
Status: offline
I had same problem with mine. I have a dual-nic setup as well. I fixed the problem finally this morning by taking off the default gateway address from the internal nic. I used to have it set to the address of the external NIC IP address. I left it blank and said ok. Problem fixed. No false spoof errors since. [Smile]

(in reply to asimmoin)
Post #: 14
RE: Error 15108 Spoof Attack - 23.Dec.2004 1:29:00 AM   
textguru

 

Posts: 223
Joined: 4.May2004
From: Philippines
Status: offline
Before I experience that problem until I blocked that IP Address on my router [Big Grin]

(in reply to asimmoin)
Post #: 15
RE: Error 15108 Spoof Attack - 1.Aug.2006 3:31:04 PM   
Xuser

 

Posts: 232
Joined: 29.Jan.2002
From: Canada
Status: offline
I removed the gateway IP and left it blank according to MS article, just like yours, but still getting the spoof IP attack msg.  These IP addr are from the IPs of my VPN users.  What I've done was reserved a set of IPs in my DHCP server for these VPN users.  My LAT looks fine.  So what could be the problem?  I've got ISA server 2004 SP2 installed.

(in reply to mgqa)
Post #: 16

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA Server 2000 General] >> General >> Error 15108 Spoof Attack Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts