republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Cisco ASDM Log (Deny Reverse Path Check)
Search Topic:
Uniqs:
305
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Stupid User Tricks: Password Selection - "WORD1" »
« Wired ADSL modem security configurations  
AuthorAll Replies


tekmunki
Tekmunki
Premium
join:2001-12-06
Lake City, FL
clubs:
·NuVox Communications
·Comcast


edit:
June 27th, @01:31PM

 Cisco ASDM Log (Deny Reverse Path Check)

Click for full size
I started seeing these in my Cisco 5520 logs... Any idea what could be causing it?

My "INSIDE" network is 172.168.0.0/16

Should I be concerned? The IP is an internal reserved, I assume something is misconfigured internally- however, tracking it could be a feat.


Lanik
Lab-nik
Premium,ExMod 2002-03
join:2001-06-25
Bay Area
·DSL EXTREME

said by tekmunki See Profile :

... I assume something is misconfigured internally- however, tracking it could be a feat.
That would be my first guess. How many clients are connected to this router?
--
"If it ain't broke don't fix it."

bmn
? ? ?
Premium,ExMod 2003-06
join:2001-03-15
hiatus
·Packet8
·Cox HSI

reply to tekmunki
»forums.cisco.com/eforum/servlet/···1dd9020e

As for tracking it down... You could try logging into the CLI of the ASA, get the MAC address (it should have it in it's cache) and then do a lookup of the manufacturer. Assuming you have managed switches, you can then login to the various switches and track the MAC address down to a specific switch port.

Used to do this kind of stuff all the time. We wouldn't know the exact location of a system, so we would follow the ports where the MAC address is showing up back to the last switch and we would find the port it is attached to.
--
Prove it...
Save the Internet Time (NTP) service, use the pool.


tekmunki
Tekmunki
Premium
join:2001-12-06
Lake City, FL
clubs:
·NuVox Communications
·Comcast

"show arp" didn't give me anything related to the 169 addresses, what other method did you have in mind to find the mac?

I can easily track the mac down if I can find it.
--
TekMunki
"There are 10 types of people in this world, those who understand binary and those who don't."

www.tekmunki.com


tekmunki
Tekmunki
Premium
join:2001-12-06
Lake City, FL
clubs:
·NuVox Communications
·Comcast

reply to Lanik
said by Lanik See Profile :

said by tekmunki See Profile :

... I assume something is misconfigured internally- however, tracking it could be a feat.
That would be my first guess. How many clients are connected to this router?
Today, only around 50 clients.
--
TekMunki
"There are 10 types of people in this world, those who understand binary and those who don't."

www.tekmunki.com

bmn
? ? ?
Premium,ExMod 2003-06
join:2001-03-15
hiatus
·Packet8
·Cox HSI


edit:
June 28th, @02:50PM

reply to tekmunki
said by tekmunki See Profile :

"show arp" didn't give me anything related to the 169 addresses, what other method did you have in mind to find the mac?

I can easily track the mac down if I can find it.
You will need a hub that you can place between all the uplinks to the router and the actual router itself. You will then need to download Wireshark ( »www.wireshark.org/ ) and capture packets from the wire in promiscuous mode to grab the MAC address.

If you don't have a hub, you'll have to use port mirroring. Port mirroring is the preferred method, BTW, as it will cause the least amount of disruption to the network.

Ignore the port mirroring part... Just realized you are using an ASA and it doesn't have the ports to do it IIRC (you need at least TWO on the LAN side).
--
Prove it...
Save the Internet Time (NTP) service, use the pool.
-
Forums » Up and Running » Security » SecurityStupid User Tricks: Password Selection - "WORD1" »
« Wired ADSL modem security configurations  


Saturday, 30-Aug 07:34:52 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [333] Comcast 250GB Cap Goes Live October 1
· [223] FBI To Allow Warrantless Investigations
· [159] Industry Reacts To Comcast Cap Plans
· [130] AT&T Thanks Democrats For Telecom Immunity
· [123] Time Warner Cable Cripples TiVO, Gets FCC Fine
· [120] Why Run FTTH When You Can Pretend You Do?
· [73] Friday Open Thread
· [67] Telus CAPS 'Unlimited' EVDO Data Plans
· [65] Game Publishers Follow The RIAA's Lead
· [60] Qwest Defends Not Running FTTH
Most people now reading
· Bandwidth Monitor for Computers-Suggestions? [Comcast HSI]
· [iPhone] Did I Buy A Fake iPhone? [All things Macintosh]
· Comcast has new Acceptable Use Policy besides the 250GB cap [Comcast HSI]
· Steele vs Paypal - Hoax or Not - You Make the Call [Spam, Scam and Phishbusters]
· [new technologies] New Actiontec MI424-WR replacement FROM VERIZ [Verizon Fiber Optics]
· Battlegrounds Auto-queue, Auto-Join Add-ons [World of Warcraft]
· Unlocking Factory Reset sunrocket linksys 2102-R. [Teleblend]
· If anyone wants to see pictures [Home Repair & Improvement]