Wireshark output.

Keith <[email protected]>
Newsgroups gmane.org.operators.internet-access
Message-ID <[email protected]>
Wondering if someone can explain a network sniff that me and another
fellow did this morning.

He has an ASA connected to our 3560. I am going to use a fake IP for his
ASA.

So his ASA is on a Vlan. His ASA outside IP is 192.168.191.33/27. The
inside IP on the ASA is 10.2.1.1/24.

Behind the ASA is another machine on 10.2.1.40.

He is seeing traffic on his ASA that concerns him.

Log from the ASA:

Built outbound TCP connection for outside IP of 10.10.10.26 to inside IP
of 10.2.1.40.

The next entry is that the ASA tears down the TCP connection.

He does not have anything on 10.10.10.26 network at all.

So we use wireshark and span his port on that his ASA is connected to on
the 3560 to see what is there. Spanning is in both directions.

Wireshark caught some traffic showing the source IP is 192.168.191.33 and
the destination IP is 10.10.10.26.

So we don't know why we would be seeing traffic with a source of his ASA
outside IP and the dest IP of 10.10.10.26, yet on his ASA logs see the
outside IP of 10.10.10.26 making a TCP connection to 10.2.1.40.

Are we seeing someone spoofing his outside ASA IP? Or is someone spoofing
using 10.10.10.26 which makes it through his ASA?

Anyone have a clue to lend?

Thanks.
-- 
Eat sushi frequently. - Avi
[email protected] is the human contact address.
[email protected] is the list posting address.
See below URL for subscribe/unsubscribe and list options:
http://inet-access.net/mailman/listinfo/list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.