Current SG135 UTM9 machine connected to internal LAN (172.16.199.1/24) on eth0 and WAN on eth1. The lag0 interface includes eth2-eth5. No IP on lag0 but there are a few VLAN interfaces on top of it - i.e. lag0.200, lag0.201, etc. The 20x VLANs are using 172.16.20x.1/24 subnets and the firewall is .1. Spoof Protection under Firewall > Advanced is set to Normal.
I have a NAS appliance running Samba under the hood an FreeBSD. It is connected to the LAN and also has interfaces on the same networks as the firewall's lag0.20x interfaces. I'm seeing regular broadcasts from the NAS (172.16.199.50:138→172.16.199.255:138) ending up in my firewall log.
I've logged into the firewall and sniffed traffic on different interfaces looking for these packets and I only ever see them on the eth0 interface where I expect them. Why is the firewall improperly (IMHO) reporting these as spoofed?
This thread was automatically locked due to age.