Tracking a Spoofed IP

Unanswered Question
Oct 21st, 2009
User Badges:

Hi all,

Currently I am having an issue with a host on the private MPLS network who is attempting to setup connections to random hosts on port 445. This host is using a spoofed IP address to do the work, and it doesn't seem that he is sequentially moving through the IP ranges. I have engaged our service provider to see if they can help track the host over the MPLS.

So far, I have not been able to find a reliable way to find this host. I have a network tool spanning our main MPLS pipe into our Data Center, and I can see that some hosts are attempting to reply, but the spoofed IP is not a routable address on our network. Therefore this host is not replicating itself, but instead just cause alarms to go off and the increase in resources to move these packets through.

Anyone have any ideas on how to track this host to a certain area?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Panos Kampanakis Wed, 10/21/2009 - 17:52
User Badges:
  • Cisco Employee,

Have a ACE rule that matches on the port 445 and have it log.

Send the logs to a syslogs server and monitor those. These logs should point you to that host real time.

I hope it helps.



This Discussion