- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- address spoofing from a website address
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
address spoofing from a website address
Good afternoon
Could you please tell me what can be the reason for antispoofing (address spoofing) logs from the site address to the host.
We see the usual addresses to the host, they accept. We also see reverse traffic from the site to the host on TCP high ports (65000-65600) and they Detect on address spoofing. At the same time the site itself does not open for the user. The site is in the rule Bypass HTTPS inspection.
Thanks in advance for your help!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check if the GW that enforce this traffic has route to the subnet and that it appears in the network topology.
Usually when clicking the get IFs with topology it brings all the subnet that has route on the GW.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would say you need to determine which one of below applies, because based on that, you can take appropriate action.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Antispoofing logs associated with traffic not working are almost always caused by routing problems. Check to be sure your firewall can route to both the client and the server.
