Hi Ray,

Thanks for the quick post/suggestion. Howver, I've rebooted both the
enforcement module and the management module a couple of times already after
the IP change.

Sorry, I forgot to mention, we're using a distributed system; the enfocement
module is running SPLAT and the management module is running on Win 2000 SP4
server (fully patched).

ta
czar
 

-----Original Message-----
From: Mailing list for discussion of Firewall-1
[mailto:[email protected]] On Behalf Of Ray
Sent: Saturday, 15 January 2011 4:16 PM
To: [email protected]
Subject: Re: [FW-1] Local Interface Address Spoofing

Did you reboot the firewall after changing the IP address?

We just had this occur in this way. We have two firewalls and decided to
move the Internet line from firewall A to firewall B. B is the test system,
A is production. The ISP on firewall B was high cost and the bandwidth was
the same as A. We then put a new higher bandwidth ISP on A. So B got the
external IP that previously was on A and A got a brand new one. 

Every time we tried to connect from B to A, it generated a Local Interface
Address Spoofing error on A. Firewall A did not show the old address
anywhere, not in any config file, not in the dbEdit database, not in ARP
tables, absolutely nowhere that we could find. Using NAT on B, we NATted all
traffic to a slightly different external IP address than the one that was
originally on A and everything worked. That confirmed to us that A thought
it still had the old IP address somewhere.

The only way we could clear the error was to reboot A. It cleared
immediately and never reoccurred. 

You're seeing this on the internal IP address and it's intermittent so it
may be something totally different but i thought maybe you did not reboot
the firewall after re-IP'ing.

FWIW,

Ray

> Date: Sat, 15 Jan 2011 11:50:13 +1100
> From: [email protected]
> Subject: [FW-1] Local Interface Address Spoofing
> To: [email protected]
> 
> Hi,
>  
> We're getting now "Local Interface Address Spoofing" message_info. 
> this normal occurs just before an IKE key exchange renewal. This is 
> occuring more frequently, at least once in the morning and once in the
afternoon.
>  
> When this happens, our site-to-site links (one to a Cisco PIX (an ISP) 
> and the other to an OpenSwan running on Debian - it's an ISP) does not 
> work. So, I have to do a cpstop/cpstart to force the links to do a key 
> exchange. A policy push/install does not resolve the issue.
>  
> Normally, the vpn to the Cisco PIX comes again immediately after doing 
> the cpstop/cpstart whereas the link the OpenSwan takes awhile to work 
> back again.
>  
> From the ISP running the openswan, their logs show that our fw1 is 
> trying to communicate using the address of the internal interface 
> instead of the address of the external interface. We could get the 
> logs from the ISP running the Cisco PIX.
>  
> From the ISP operating the Cisco PIX, they're claiming that our 
> external address is not configured for the crypto. Unfortunately, this 
> is the most important site as many of our staff rdp's to the hosted VM's
there.
>  
> This issue started happening after we change the address of the 
> internal interface of our fw1. The vpn links are configured to 
> communicate to the external interface of FW1.
>  
> We're still running R55 NGAI HFA20 (we're going to upgrade to R75 
> blades hopefully soon rather than later). We have lots of VLAN's 
> behind the internal interface that connects to the hosted VM's. So 
> far, all routing are working correctly (unless I've missed something).
>  
> The key to the resolution of the issue is to resolve the "Local 
> Interface Address Spoofing" error.
>  
> I've searched the Net, CP KnowledgeBase, etc. The solutions put 
> forward such as disabling the Anti-spoofing ,etc, does not work.
>  
> Any ideas for the resolution of the problem is greatly appreciated.
>  
> ta
> czar
> 
> =================================================
> To set vacation, Out-Of-Office, or away messages, send an email to 
> [email protected]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list, please see the instructions at 
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your subscription options, 
> email [email protected] 
> =================================================
> 
> Scanned by Check Point Total Security Gateway.
                                          


Scanned by Check Point Total Security Gateway.


=================================================
To set vacation, Out-Of-Office, or away messages, send an email to
[email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your subscription options, email
[email protected]
=================================================

Scanned by Check Point Total Security Gateway.



Scanned by Check Point Total Security Gateway.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================

Reply via email to