Hi everyone,
I was wondering if anyone else has seen Win98SE machines
doing arp queries like these:
Times Source MAC Source IP Destination MAC
----- -------------- ----------------- -----------------------
1071 0008:c763:223c srcip=50.46.234.0 destenet=0100:0000:0000
181 0008:c763:223c srcip=50.46.234.0 destenet=0100:044a:0bbf
377 0010:a701:8a7b srcip=50.46.234.0 destenet=0100:0000:0000
30 0010:a701:8a7b srcip=50.46.234.0 destenet=0100:044a:0bbf
147 0020:18a0:395d srcip=50.46.234.0 destenet=0100:0000:0000
754 0060:5209:acfd srcip=50.46.234.0 destenet=0100:0000:0000
7 0060:5209:acfd srcip=50.46.234.0 destenet=0100:0000:0000
120 0060:5209:acfd srcip=50.46.234.0 destenet=0100:044a:0bbf
220 0080:ad97:9088 srcip=50.46.234.0 destenet=0100:0000:0000
20 0080:ad97:9088 srcip=50.46.234.0 destenet=0100:044a:0bbf
These are five unique machines that are having problems doing
ARP queries to our gateways, for obvious reasons.
We just enabled source address filtering in ARP requests, and
started getting drops galore.
The funny thing is that noone here has the source ip "50.46.234.0"
(I've verified their setup) and another funny thing is that half
of these are requests, so the destination address
should be 0000:0000:0000 (i.e. "not set")
?
/Mike
--
Mikael Olsson, EnterNet Sweden AB, Box 393, S-891 28 �RNSK�LDSVIK
Phone: +46 (0)660 105 50 Fax: +46 (0)660 122 50
Mobile: +46 (0)70 66 77 636
WWW: http://www.enternet.se E-mail: [EMAIL PROTECTED]
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]