Re: possible causes of source and destination ip from external network

From: Stephen Samuel (samuel_at_bcgreen.com)
Date: 06/27/04

  • Next message: Michael H. Warfield: "Re: SSL and IPS (was RE: ssh and ids)"
    Date: Sat, 26 Jun 2004 22:29:03 -0700
    To: Annie Green <annie_r_green@hotmail.com>
    
    

    One of the questions I would ask, in terms of determining what's happening
    is: "what interface are these packets arriving on? You have a different
    set of issues to deal with if it's coming from the inside than you do if
    it's cominmg from the outside.

    You should be able to determine this if your IDS/firewall logs either of
    the actual interface, or the source/destination MAC address of the
    packets in question.

    Mac addresses require an extra step to help figure out where a packet
    is arriving, but they also give you some hope of tracking which station
    (or router) the packets came from

    Annie Green wrote:
    > Hi all
    >
    > What would be the possible causes of the IDS alert that shows source ip
    > and destination ip from external network? Also, why did the router route
    > this packet in the first place?
    >
    > Regards,
    > A.
    >

    -- 
    Stephen Samuel +1(604)876-0426                samuel@bcgreen.com
    		   http://www.bcgreen.com/~samuel/
        Powerful committed communication. Transformation touching
          the jewel within each person and bringing it to light.
    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------
    

  • Next message: Michael H. Warfield: "Re: SSL and IPS (was RE: ssh and ids)"

    Relevant Pages

    • Terminal Server Setup
      ... description GRE Tunnel Source Interface ... input packets with dribble condition detected ... output buffer failures, ... Serial1/0 is up, line protocol is up ...
      (comp.dcom.sys.cisco)
    • Re: Tuning ADSL lines on Ciscos roputer - LONG -
      ... Last clearing of "show interface" counters never ... minute input rate 0 bits/sec, ... input packets with dribble condition detected ... output buffer failures, ...
      (comp.dcom.sys.cisco)
    • Re: Terminal Server Setup
      ... description GRE Tunnel Source Interface ... input packets with dribble condition detected ... output buffer failures, ...
      (comp.dcom.sys.cisco)
    • Re: Excessive interface resets on Cisco 1841 and FIOS line
      ... huge amount of interface resets on the WAN interface, ... access-list 4 remark HTTP Access-class list ... input packets with dribble condition detected ... output buffer failures, ...
      (comp.dcom.sys.cisco)
    • Interface counters not working
      ... get why no traffic is registering on the interface counters. ... minute input rate 0 bits/sec, ... input packets with dribble condition detected ... output buffer failures, ...
      (comp.dcom.sys.cisco)