Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Moudar
Advisor

Address spoofing

Hi

I  am getting this kind of logs:

kort.JPG

I have 10.10.32.1/19 configured on Bond0.409:

show interface bond0.409
state on
mac-addr 00:1c:7f:67:3c:a8
type vlan
link-state not available
mtu 1500
auto-negotiation off (bond0)
speed 20G (bond0)
ipv6-autoconfig Not configured
monitor-mode Not configured
duplex full (bond0)
link-speed Not configured
comments bond0.409
ipv4-address 10.10.32.7/19

But still all Bond0.409 goes out from Bond0.530!

There is no static route that route 409 to 530!

 

But still all traffic coming from 10.10.32.1/19 devices is going out through bond 530 with Address Spoofing, and Bond0.409 shows no logs.

 

Any ideas!

0 Kudos
3 Replies
Chris_Atkinson
Employee Employee
Employee

To start what is the IP & netmask config of Bond0.530 please?

CCSM R77/R80/ELITE
0 Kudos
Moudar
Advisor

Bond0.530 is 10.4.0.1/24

0 Kudos
Chris_Atkinson
Employee Employee
Employee

I suspect a downstream device may have incorrect routing.

But please check the firewall has the correct and available route(s) for:

0.0.0.0/0 and 20.100.141.113/32

 

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events