I'm playing around with the Cisco ASDM with an ASA5520, only the internal
interface is connected, and I enabled the reverse path check (rpc)
anti-spoofing and within a minute I'm getting syslog warnings of
Deny ICMP [or UDP] reverse path check from 192.168.1.1 to 192.168.xxx.xxx
[so far only 2 internal addresses] on interface [internal interface]
The came in groups of three, first UDP then ICMP, other then putting on a
sniffer and waiting for them to reoccur what's a good way to track these
down? Its now been about 20 minutes since the last round. I'm I reading this
wrong and there isn't a reason to be concerned?
--
Posted via a free Usenet account from http://www.teranews.com
|
|
0
|
|
|
|
Reply
|
RC
|
5/30/2007 10:32:38 PM |
|