RE: IP spoofing

Tech-Archive recommends: Fix windows errors by optimizing your registry



I found the solution modifying the registry:
Use this page:
http://support.microsoft.com/kb/917025

"Damon" wrote:

I've got a new problem with an incoming VPN. It has been working fine but
now to one server it can't ping or access them and if I check in the alerts
I get an IP spoofing alert from its IP saying the following:

IP spoofing

Description: ISA Server detected a spoof attack from Internet Protocal (IP)
address 10.1.0.3. A spoof attack occurs when an IP address that is not
reachable via the interface on which the packet was received. If logging for
the dropped packets is set, you can view details in the firewall log.

The VPN clients are on a static address poll of 10..0.0 to 10.1.0.255

They are connecting to a 10.2.*.* range

Any idea on what is going on or how to fix this?

Cheers

Damon



.



Relevant Pages

  • IP spoofing
    ... I've got a new problem with an incoming VPN. ... ISA Server detected a spoof attack from Internet Protocal ... the dropped packets is set, you can view details in the firewall log. ...
    (microsoft.public.isa.vpn)
  • Re: Error ID 1016 (Network Compromise)
    ... > Windows 2000 Server. ... >> domain\username's mailbox and is not the Primary WinNT account. ... >> Best Regards, Damon N. ...
    (microsoft.public.exchange.admin)
  • Re: IP SPOOFING
    ... to switch and modem router is connected to switch also ... gateway;dns server 1 & 2 given by ISP and Netbios over ... >The fact that you're receiving a spoof attack for what ... misconfigured your ISA ...
    (microsoft.public.isa)
  • Re: LDAP authentication via dsee6
    ... Damon> load of users logging in and out of GNOME via terminals. ... Damon> here and I need some centralized authentication so that we can make ... Damon> changes through an LDAP database instead of manually editing /etc/ ... Damon> existing LDAP server to serve all of the information that we currently ...
    (comp.os.linux.networking)
  • Re: NTP Synch
    ... What isn't working is getting this DC to synch up with an external time source. ... The local firewall is disabled because...well..it's an MS firewall. ... Our CheckPoint firewall has a rule stating that this server can go to 1 of 3 servers over UDP123 and TCP123. ... I see no accept or dropped packets from this server yet I do see dropped packets from a contractor's PC since 1) they are not joined to our domain and ...
    (microsoft.public.windows.server.general)