Hi everybody, We have a FW1 v4.1 running on a Ultra 5 box (Solaris 2.6). The configuration is classic : Internal LAN -> qfe0 DMZ -> qfe1 Internet -> hme0 The internal LAN addresses are 192.168.something and the anti-spoofing is on. The problem is that I had an alert saying that some valid address (not one of ours) has been detected on the internal LAN (Antispoof alert). This valid address is resolved into an public ISP client. Where can this come from ? I forbid the use of modems on the LAN (could this be it anyway ?). Could this be a successful intrusion into our systems ? How can I track that ? I looked at the arp table but I could not find the alien address in the table (too late ?). Any help appreciated a lot, Karim AMRANI
begin:vcard n:AMRANI;Karim tel;cell:00 33 6 14 64 72 28 tel;fax:00 33 5 46 28 15 01 tel;work:00 33 5 46 28 15 00 x-mozilla-html:TRUE url:www.pole-n.com org:COGELOG/Pole-N adr:;;;La Rochelle;;17000;France version:2.1 email;internet:[EMAIL PROTECTED] title:Architecte R�seaux fn:Karim AMRANI end:vcard
