Re: ARP Input Problem [7:13003]

2001-07-21 Thread Chuck Larrieu
I'm hoping you will be able to provide a follow up report for this problem. I am curious if your client has discovered they have been victimized by code red, and that their IIS boxes have been compromised. In terms of relevance to groupstudy, your discoveries will be relevant as well. when

RE: ARP Input Problem [7:13003]

2001-07-21 Thread Daniel Cotts
Something like this is discussed in the Cisco Press book Advanced IP Network Design. If they have a default route out to you over an Ethernet link and that route statement specifies their outbound interface rather than the ip address of your interface, then their router will have to ARP for every

Re: ARP Input Problem [7:13003]

2001-07-19 Thread Jaspreet Bhatia
ARe you using IOS ver 11.2 ? see this link http://www.cisco.com/warp/public/770/fa112-arp_eigrp.shtml clear the arp table and configure a static arp entry and see if that works ? Let me know what works eventually ? Jaspreet Chris Headings wrote: I have a weird onewe have a client that

Re: ARP Input Problem [7:13003]

2001-07-19 Thread Chris Headings
We are using 12.0(7)T for the IOS Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=13013t=13003 -- FAQ, list archives, and subscription info: http://www.groupstudy.com/list/cisco.html Report misconduct and Nondisclosure violations

Re: ARP Input Problem [7:13003]

2001-07-19 Thread Chris Headings
Alsohow can I filter a MAC addressfound one from the mac-accounting that looks suspicious??? Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=13014t=13003 -- FAQ, list archives, and subscription info:

RE: ARP Input Problem [7:13003]

2001-07-19 Thread Chuck Larrieu
connected to a client how? over on the NANOG list today there is a long discussion about Code Red. the following is an excerpt from one of the mails: --- Here at Merit we are seeing large numbers of Code Red infected hosts. These hosts may be on our regional network MichNet or they may

RE: ARP Input Problem [7:13003]

2001-07-19 Thread Chris Headings
Will look into thisTHX! The client behind this attack is a small web hosting company Message Posted at: http://www.groupstudy.com/form/read.php?f=7i=13043t=13003 -- FAQ, list archives, and subscription info: