<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Cisco ASDM Log (Deny Reverse Path Check) in Security</title>
<link>http://www.dslreports.com/forum/r18575729</link>
<description></description>
<language>en</language>
<pubDate>Sat, 05 Dec 2009 16:28:21 EDT</pubDate>
<lastBuildDate>Sat, 05 Dec 2009 16:28:21 EDT</lastBuildDate>

<item>
<title>Re: Cisco ASDM Log (Deny Reverse Path Check)</title>
<link>http://www.dslreports.com/forum/remark,18581760</link>
<description><![CDATA[<A HREF="/useremail/u/344321"><b>bmn</b></A> : <div class="bquote"><SMALL>said by  tekmunki <A HREF="/useremail/u/532180"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>"show arp" didn't give me anything related to the 169 addresses,  what other method did you have in mind to find the mac?<br><br>I can easily track the mac down if I can find it.  :)<br> </DIV>You will need a hub that you can place between all the uplinks to the router and the actual router itself.   You will then need to download Wireshark ( &raquo;<A HREF="http://www.wireshark.org/" >www.wireshark.org/</A> ) and capture packets from the wire in promiscuous mode to grab the MAC address.<br><br><STRIKE>If you don't have a hub, you'll have to use port mirroring.   Port mirroring is the preferred method, BTW, as it will cause the least amount of disruption to the network.</STRIKE><br><br>Ignore the port mirroring part... Just realized you are using an ASA and it doesn't have the ports to do it IIRC (you need at least TWO on the LAN side).<br><SMALL>--<br>Prove it...<B><br><A HREF="http://www.pool.ntp.org">Save the Internet Time (NTP) service, use the pool.</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18581760</guid>
<pubDate>Thu, 28 Jun 2007 14:48:44 EDT</pubDate>
</item>

<item>
<title>Re: Cisco ASDM Log (Deny Reverse Path Check)</title>
<link>http://www.dslreports.com/forum/remark,18580528</link>
<description><![CDATA[<A HREF="/useremail/u/532180"><b>tekmunki</b></A> : <div class="bquote"><SMALL>said by  Lanik <A HREF="/useremail/u/418397"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br><div class="bquote"><SMALL>said by  tekmunki <A HREF="/useremail/u/532180"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>... I assume something is misconfigured internally- however, tracking it could be a feat.  :o<br> </DIV>That would be my first guess.  How many clients are connected to this router?<br> </DIV>Today, only around 50 clients.<br><SMALL>--<br>TekMunki<BR>"There are 10 types of people in this world, those who understand binary and those who don't."<BR><BR><A HREF="http://www.tekmunki.com">www.tekmunki.com</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18580528</guid>
<pubDate>Thu, 28 Jun 2007 10:40:06 EDT</pubDate>
</item>

<item>
<title>Re: Cisco ASDM Log (Deny Reverse Path Check)</title>
<link>http://www.dslreports.com/forum/remark,18580504</link>
<description><![CDATA[<A HREF="/useremail/u/532180"><b>tekmunki</b></A> : "show arp" didn't give me anything related to the 169 addresses,  what other method did you have in mind to find the mac?<br><br>I can easily track the mac down if I can find it.  :)<br><SMALL>--<br>TekMunki<BR>"There are 10 types of people in this world, those who understand binary and those who don't."<BR><BR><A HREF="http://www.tekmunki.com">www.tekmunki.com</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18580504</guid>
<pubDate>Thu, 28 Jun 2007 10:34:12 EDT</pubDate>
</item>

<item>
<title>Re: Cisco ASDM Log (Deny Reverse Path Check)</title>
<link>http://www.dslreports.com/forum/remark,18579703</link>
<description><![CDATA[<A HREF="/useremail/u/344321"><b>bmn</b></A> : &raquo;<A HREF="http://forums.cisco.com/eforum/servlet/NetProf;jsessionid=uo4xfyba61.SJ1A?page=netprof&forum=Security&topic=General&CommCmd=MB%3Fcmd%3Ddisplay_location%26location%3D.1dd9020e" >forums.cisco.com/eforum/servlet/&middot;&middot;&middot;1dd9020e</A><br><br>As for tracking it down...   You could try logging into the CLI of the ASA, get the MAC address (it <I>should</I> have it in it's cache) and then do a lookup of the manufacturer.   Assuming you have managed switches, you can then login to the various switches and track the MAC address down to a specific switch port.<br><br>Used to do this kind of stuff all the time.   We wouldn't know the exact location of a system, so we would follow the ports where the MAC address is showing up back to the last switch and we would find the port it is attached to.<br><SMALL>--<br>Prove it...<B><br><A HREF="http://www.pool.ntp.org">Save the Internet Time (NTP) service, use the pool.</A></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18579703</guid>
<pubDate>Thu, 28 Jun 2007 04:58:07 EDT</pubDate>
</item>

<item>
<title>Re: Cisco ASDM Log (Deny Reverse Path Check)</title>
<link>http://www.dslreports.com/forum/remark,18576739</link>
<description><![CDATA[<A HREF="/useremail/u/418397"><b>Lanik</b></A> : <div class="bquote"><SMALL>said by  tekmunki <A HREF="/useremail/u/532180"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>... I assume something is misconfigured internally- however, tracking it could be a feat.  :o<br> </DIV>That would be my first guess.  How many clients are connected to this router?<br><SMALL>--<br>"If it ain't broke don't fix it."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18576739</guid>
<pubDate>Wed, 27 Jun 2007 16:45:20 EDT</pubDate>
</item>

<item>
<title>Cisco ASDM Log (Deny Reverse Path Check)</title>
<link>http://www.dslreports.com/forum/remark,18575729</link>
<description><![CDATA[<A HREF="/useremail/u/532180"><b>tekmunki</b></A> : I started seeing these in my Cisco 5520 logs...  Any idea what could be causing it? <br><br>My "INSIDE" network is 172.168.0.0/16<br><br>Should I be concerned?   The IP is an internal reserved, I assume something is misconfigured internally- however, tracking it could be a feat.  :o<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#000000 nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/18575729?c=1180618&ret=L2ZvcnVtL3IxODU3NTcyOS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="48979 bytes" WIDTH=600 HEIGHT=120 SRC="/r0/download/1180618.thumb600~38e2c401fe0aca7ac66c992ee8698978/asdm.jpg/thumb.jpg" ALT="Click for full size"></A></TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,18575729</guid>
<pubDate>Wed, 27 Jun 2007 13:29:36 EDT</pubDate>
</item>

</channel>
</rss>
