Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Matlu
MVP Silver
MVP Silver

Meaning of Address Spoofing

Hello, everybody.

I have a curiosity about "Address Spoofing".
It is clear to me that when the log shows you a "DETECT" action, the traffic is "allowed", but is it important to "check" the reason for this traffic?

SPO1.png

Having this type of logs, can give us "indications" of "Networking" problems in the network of a company?

I want to communicate to IP:172.23.12.5 with IP:172.23.3.21, but there is no traffic registered in the CP.

I have policies, I have routes, I have tried with "TCPDUMP" "CPPCAP" "FW MONITOR", but none of these tools show me traffic, when traffic is generated (a simple PING, or a Telnet to any port).

When I "search" in the logs for the origin with IP:172.23.12.5, I only get irrelevant traffic to "other IPs" that have nothing to do with my target.

Could this be a routing problem?

Cheers :).

0 Kudos
6 Replies
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.
This widget could not be displayed.