CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > SmartDefense
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-13
DrkNite DrkNite is offline
Junior Member
 
Join Date: 2007-11-18
Posts: 14
Rep Power: 0
DrkNite has an average reputation (10+)
Default Address Spoofing Alert

I'm seeing a lot of Address Spoofing Alert in the SmartDefence logs
but not getting a lot of info off of the log file it's self

Number: 499485
Date: 13May2008
Time: 11:00:19
Product: SmartDefense
Attack: Address Spoofing
Origin: gatecontrol
Type: Alert
Action:
Information: cpmad: CPMAD

above is all i'm getting
gatecontrol is the name of my SmartCenter Box
could this be a problem with my cluster servers
we did have a router turned on and put on the same ip as the virtual NIC of the cluster at which time the cluster was rebooted before we found out what had happened. the router was shut down and all was fine again it wasn't till a few days later is saw the alerts in the logs and they have continued ever since

however it it was the cluster I would have expected the error to come from them not smartcenter

Last edited by DrkNite; 2008-05-13 at 08:11.
Reply With Quote
  #2 (permalink)  
Old 2008-05-13
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 346
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Address Spoofing Alert

What kind of traffic is causing those errors? The source IP should give you clues as to what it might be.
Reply With Quote
  #3 (permalink)  
Old 2008-05-13
DrkNite DrkNite is offline
Junior Member
 
Join Date: 2007-11-18
Posts: 14
Rep Power: 0
DrkNite has an average reputation (10+)
Default Re: Address Spoofing Alert

thats the problem I'm not seeing a source address
everything showing in the log i put in the previous post, thats what makes this odd!
Reply With Quote
  #4 (permalink)  
Old 2008-05-14
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 346
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Address Spoofing Alert

What platforms are you running? That does seem strange.
Reply With Quote
  #5 (permalink)  
Old 2008-05-15
DrkNite DrkNite is offline
Junior Member
 
Join Date: 2007-11-18
Posts: 14
Rep Power: 0
DrkNite has an average reputation (10+)
Default Re: Address Spoofing Alert

I'm running R65 on

1 two box cluster Gateway
1 single box Gateway
1 smartcenter
All are running SPLAT
Reply With Quote
  #6 (permalink)  
Old 2008-05-16
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 346
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Address Spoofing Alert

On the "SmartDefense" Policy tab, if you go to "Network Security->Anti Spoofing configuration status", what does it show? Maybe check all the objects individually and make sure all is fine?
Reply With Quote
  #7 (permalink)  
Old 4 Weeks Ago
kidem kidem is offline
Junior Member
 
Join Date: 2006-11-30
Posts: 20
Rep Power: 0
kidem has an average reputation (10+)
Default Re: Address Spoofing Alert

I have the same issue.... did u figure yours out? I get like 500 a day

here is my errorAddress Spoofing


SRVR is the Smartcenterserver

Number: 300304
Date: 5Jun2008
Time: 8:31:35
Product: SmartDefense
Attack: Address Spoofing
Origin: SRVR << this is the Smartcenter server
Type: Alert
Action:
Information: cpmad: CPMAD

Any ideas?
__________________
4 - Nokia IP560's NGX (R65) HFA_02, Hotfix 602
Two Clusters

Last edited by kidem; 4 Weeks Ago at 08:02.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 14:57.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0