Finding spoofed IP address on network
Posted
by
Jared
on Server Fault
See other posts from Server Fault
or by Jared
Published on 2012-11-23T13:39:34Z
Indexed on
2012/11/23
17:09 UTC
Read the original article
Hit count: 255
I have a few IP spoof dropped messages coming out of my Sonicwall firewall, we'll call them Source A and Source B. Both of these sources have the same mac address indicating they're coming from the layer 3 switch behind my firewall. Source A has an ip within a valid subnet on my network and it shows up in the ARP table of my layer 3 switch. I was able to trace the exact location and fix the issue. Source B's ip however, is not within valid subnet on my network and it's not showing up in my layer 3 switches arp table. Any idea how I can trace the location of this device within my network?
Thanks in advance.
© Server Fault or respective owner