Hi,
This is probably something really simply, but I cannot sort out why.
I have an internal network on x.y.40.* and a DMZ network on x.y.80.* (x and y are the same on both networks). The two networks have no connection between them. I have recently placed a program on the DMZ that emails reports. I have configured the SMTP server to listen on the DMZ network. However, when a report is emailed, I get the following messages in the logs
May 11 08:52:38 (none) kernel: IP-SPOOFING Drop: IN=eth2 OUT= MAC=00:05:5d:a1[:D]3:46:00:02:b3:25:a5:9f:08:00 SRC=x.y.80.102 DST=x.y.80.254 LEN=48 TOS=0x00 PREC=0x00 TTL=128 ID=37717 DF PROTO=TCP SPT=4761 DPT=25 WINDOW=16384 RES=0x00 SYN URGP=0
I am get the same kind of messages on port 137 as well, but that's Windows for you [:)]
Anybody got any ideas why these packets are being dropped ?
Thanks in advance
ianb@iealtd.co.uk
This thread was automatically locked due to age.