Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Oliver_222
Participant

address spoofing from a website address

Good afternoon

Could you please tell me what can be the reason for antispoofing (address spoofing) logs from the site address to the host.

We see the usual addresses to the host, they accept. We also see reverse traffic from the site to the host on TCP high ports (65000-65600) and they Detect on address spoofing. At the same time the site itself does not open for the user. The site is in the rule Bypass HTTPS inspection.

Thanks in advance for your help!

 

0 Kudos
3 Replies
Amir_Senn
Employee
Employee

Check if the GW that enforce this traffic has route to the subnet and that it appears in the network topology.

Usually when clicking the get IFs with topology it brings all the subnet that has route on the GW. 

Kind regards, Amir Senn
0 Kudos
the_rock
Legend
Legend

I would say you need to determine which one of below applies, because based on that, you can take appropriate action.

Andy

 

Screenshot_1.png

 

0 Kudos
Bob_Zimmerman
Authority
Authority

Antispoofing logs associated with traffic not working are almost always caused by routing problems. Check to be sure your firewall can route to both the client and the server.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events