Hi Ray, Thanks for the quick post/suggestion. Howver, I've rebooted both the enforcement module and the management module a couple of times already after the IP change.
Sorry, I forgot to mention, we're using a distributed system; the enfocement module is running SPLAT and the management module is running on Win 2000 SP4 server (fully patched). ta czar -----Original Message----- From: Mailing list for discussion of Firewall-1 [mailto:[email protected]] On Behalf Of Ray Sent: Saturday, 15 January 2011 4:16 PM To: [email protected] Subject: Re: [FW-1] Local Interface Address Spoofing Did you reboot the firewall after changing the IP address? We just had this occur in this way. We have two firewalls and decided to move the Internet line from firewall A to firewall B. B is the test system, A is production. The ISP on firewall B was high cost and the bandwidth was the same as A. We then put a new higher bandwidth ISP on A. So B got the external IP that previously was on A and A got a brand new one. Every time we tried to connect from B to A, it generated a Local Interface Address Spoofing error on A. Firewall A did not show the old address anywhere, not in any config file, not in the dbEdit database, not in ARP tables, absolutely nowhere that we could find. Using NAT on B, we NATted all traffic to a slightly different external IP address than the one that was originally on A and everything worked. That confirmed to us that A thought it still had the old IP address somewhere. The only way we could clear the error was to reboot A. It cleared immediately and never reoccurred. You're seeing this on the internal IP address and it's intermittent so it may be something totally different but i thought maybe you did not reboot the firewall after re-IP'ing. FWIW, Ray > Date: Sat, 15 Jan 2011 11:50:13 +1100 > From: [email protected] > Subject: [FW-1] Local Interface Address Spoofing > To: [email protected] > > Hi, > > We're getting now "Local Interface Address Spoofing" message_info. > this normal occurs just before an IKE key exchange renewal. This is > occuring more frequently, at least once in the morning and once in the afternoon. > > When this happens, our site-to-site links (one to a Cisco PIX (an ISP) > and the other to an OpenSwan running on Debian - it's an ISP) does not > work. So, I have to do a cpstop/cpstart to force the links to do a key > exchange. A policy push/install does not resolve the issue. > > Normally, the vpn to the Cisco PIX comes again immediately after doing > the cpstop/cpstart whereas the link the OpenSwan takes awhile to work > back again. > > From the ISP running the openswan, their logs show that our fw1 is > trying to communicate using the address of the internal interface > instead of the address of the external interface. We could get the > logs from the ISP running the Cisco PIX. > > From the ISP operating the Cisco PIX, they're claiming that our > external address is not configured for the crypto. Unfortunately, this > is the most important site as many of our staff rdp's to the hosted VM's there. > > This issue started happening after we change the address of the > internal interface of our fw1. The vpn links are configured to > communicate to the external interface of FW1. > > We're still running R55 NGAI HFA20 (we're going to upgrade to R75 > blades hopefully soon rather than later). We have lots of VLAN's > behind the internal interface that connects to the hosted VM's. So > far, all routing are working correctly (unless I've missed something). > > The key to the resolution of the issue is to resolve the "Local > Interface Address Spoofing" error. > > I've searched the Net, CP KnowledgeBase, etc. The solutions put > forward such as disabling the Anti-spoofing ,etc, does not work. > > Any ideas for the resolution of the problem is greatly appreciated. > > ta > czar > > ================================================= > To set vacation, Out-Of-Office, or away messages, send an email to > [email protected] > in the BODY of the email add: > set fw-1-mailinglist nomail > ================================================= > To unsubscribe from this mailing list, please see the instructions at > http://www.checkpoint.com/services/mailing.html > ================================================= > If you have any questions on how to change your subscription options, > email [email protected] > ================================================= > > Scanned by Check Point Total Security Gateway. Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] ================================================= Scanned by Check Point Total Security Gateway. Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] =================================================
