This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

IP spoof question

I have IP spoofing enabled.

In the logs it shows a lot of the same address from source and destination addresses.

Is this normal ? It's an 169.254.x.x address from source.

Thank you

Brock



This thread was automatically locked due to age.
Parents Reply Children
  • Here are some logs

     

     

    2017-05-17 07:39:08
    IP Spoof
    Denied
    -
    0
    -
    -
    169.254.7.171 :UDP (42388)
    169.254.255.255 :UDP (42388)

     

    05151
    2017-05-17 07:39:07
    IP Spoof
    Denied
    -
    0
    -
    -
    169.254.7.63 :UDP (42388)
    169.254.255.255 :UDP (42388)

     

    05151
    2017-05-17 07:39:07
    IP Spoof
    Denied
    -
    0
    -
    -
    169.254.7.63 :UDP (42388)
    169.254.255.255 :UDP (42388)

     

    05151
    2017-05-17 07:39:07
    IP Spoof
    Denied
    -
    0
    -
    -
    169.254.7.63 :UDP (42388)
    169.254.255.255 :UDP (42388)

     

    05151
     
     
     
     and spoof is just enabled on the lan side. I followed a Sophos KB
     
     
     
  • It looks like some computers on your LAN are not getting a proper IP address via dhcp. The 169.254.0.0/16 range is the automatic private IP addressing range through which dhcp clients self-assign themselves IP addresses when a DHCP server is not available.

    Muhammad Osama

    Sophos Certified Engineer (XG Firewall)

  • Hello

    How would I find the out what device is causing this issue? Right now all computers and printers are functioning like they should be.