Hello all
We have an ASL 5.100 installed. There are two interfaces (dmz & an internal interace). In the packetfilter-log we reveive the following message (from the internal network):
2004:12:29-13:26:19 (none) kernel: IP-SPOOFING DROP: IN=eth1 OUT=eth2 SRC=10.1.2.10 DST=195.186.4.111 LEN=60 TOS=0x00 PREC=0x00 TTL=62 ID=23963 DF PROTO=UDP SPT=57539 DPT=53 LEN=40
Now we have the problem, that the host in the internal network couldn't start dns-querys, because they are dropped with this rule "ip-spoofing drop". the host in the internal network connects to the internet through an other host (virusgateway). could this built our problem?
I mean that I've already disabled all the intrusion-detection-settings...but this didn't solve our problems. Are there other possibilities to disable the dns-ids?
Thanks a lot.
HannesG
This thread was automatically locked due to age.