[Dshield] Spoof source query

David Sentelle David.Sentelle at cnbcbank.com
Tue Dec 9 13:38:56 GMT 2003


I'm eager to hear the answer, April.  We've got a firewall behind a
firewall behind a firewall, and the one in the middle occasionally gets
spoofed packets from inside.  I've looked into it a bit (when I first
noticed them almost 2 years ago) and I've found no explanation other
than the firewall that's sending these somehow malforms the TCP/IP
packets.  I've written it off to a bug in the inside firewall's TCP/IP
stack, or perhaps (much less likely) an incompatibility between the 2
firewalls.

If you want to email me your firewall type (offlist) I would be happy
to confirm if that's the same type of firewall I see this activity
with.





More information about the list mailing list