Hi everybody,

We have a FW1 v4.1 running on a Ultra 5 box (Solaris 2.6). The
configuration is classic :
Internal LAN -> qfe0
DMZ -> qfe1
Internet -> hme0

The internal LAN addresses are 192.168.something and the anti-spoofing
is on.

The problem is that I had an alert saying that some valid address (not
one of ours) has been detected on the internal LAN (Antispoof alert).
This valid address is resolved into an public ISP client.

Where can this come from ? I forbid the use of modems on the LAN (could
this be it anyway ?). Could this be a successful intrusion into our
systems ?

How can I track that ? I looked at the arp table but I could not find
the alien address in the table (too late ?).

Any help appreciated a lot,
Karim AMRANI
begin:vcard 
n:AMRANI;Karim
tel;cell:00 33 6 14 64 72 28
tel;fax:00 33 5 46 28 15 01
tel;work:00 33 5 46 28 15 00
x-mozilla-html:TRUE
url:www.pole-n.com
org:COGELOG/Pole-N
adr:;;;La Rochelle;;17000;France
version:2.1
email;internet:[EMAIL PROTECTED]
title:Architecte R�seaux
fn:Karim AMRANI
end:vcard

Reply via email to