Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

106016: Deny IP Spoof Error on ASA 5510

Hi All,

I am receiving a number of errors on my Cisco ASA 5510 device that reads:

106016: Deny IP spoof from (127.0.0.1) to x.x.x.x on Interface Inside

x.x.x.x is some random IP Address. There are a number of IP Addresses that are reported.

Any ideas?

5 REPLIES

Re: 106016: Deny IP Spoof Error on ASA 5510

Since that is a loopback IP, it could be any host. Probably one with vmware etc. Do a packet capture for that IP and get the mac-address. Then trace it on your network

Regards

Farrukh

New Member

Re: 106016: Deny IP Spoof Error on ASA 5510

I have to admit that the x.x.x.x ip addresses that appear are external public IP addresses that I have no idea what they are.

Also on the Internal Interface of the ASA there is an ISA Server... there is nothing between the ASA and ISA server. Is there another way of getting a packet capture without installing a hub between the ASA and the ISA... as obviously this means there will be an outage while I install the hub?

Re: 106016: Deny IP Spoof Error on ASA 5510

Well there is a capture command built-in the ASA:

http://www.cisco.com/en/US/products/ps6120/products_tech_note09186a00807c35e7.shtml#s3

Once you get the mac-address, wireshark will show you the vendor name as derived from the MAC Address OID field (or you can google it up pretty quick).

Regards

Farrukh

New Member

Re: 106016: Deny IP Spoof Error on ASA 5510

Thanks! This is somewhat helpful. From what I have found the MAC address is of the ISA server (which is the only thing that connects to the Inside interface of the ASA... no surprise really) but why?

The packet capture shows that the source IP Address is 127.0.0.1 with the MAC of the ISA server and the Destination is of various external IP Addresses with the destination MAC address of the ASA.

What can I check now?

Re: 106016: Deny IP Spoof Error on ASA 5510

I would run a whois on those external IPs to see what they are really, this might give you an idea about the traffic. What is the destination port? (If its TCP/UDP) traffic?

Download process explorer and run it on your ISA server (no need to install it,its standalone).

http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx

Check which 'service' or application is opening these connections from the ISA server. Perhaps a trojan/worm...

Regards

Farrukh

5389
Views
3
Helpful
5
Replies