Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

My DHCP address is spoofing?

I have a Laptop that goes onto our wireless network via Cisco 1100 APs. It is given a DHCP address. When it tries to access the outside world, the PIX firewall wont let it out and says its spoofing the address. Any ideas as to why? or atleast how to let it out?

Win2k sp4

Cisco 350 Aironet Adapter

Cisco 1100 AP

Cisco 506E PIX firewall

2 REPLIES
New Member

Re: My DHCP address is spoofing?

Is this the syslog message that your getting? Do a ipconfig/all on your laptop, and see if the ip address is a internal network ip address? If not do a ipconfig/release, then a ipconfig/renew, then try it your connection again.

106016

Error Message %PIX-2-106016: Deny IP spoof from (IP_address) to IP_address on interface interface_name.

This message is logged when the firewall discards a packet with an invalid source address. Invalid source addresses are those addresses belonging to the following:

Loopback network (127.0.0.0)

Broadcast (limited, net-directed, subnet-directed, and all-subnets-directed)

The destination host (land.c)

Furthermore, if the sysopt connection enforcesubnet command is enabled, PIX Firewall discards packets with a source address belonging to the destination subnet from traversing the firewall and logs this message.

New Member

Re: My DHCP address is spoofing?

I have found my SPoofing problem. AParently, my boss, who has a Static IP for his hardwire connection to our network, has also been using his wireless card at the same time, which is where the DHCP address is coming from, and he has some software that is for use with a TIVO. This is causing our Unix server to send out spoofed messages for some reason. The reason why he was having trouble getting outside our network was because he was using his hom DNS sever rather than our work one with the wireless card.

Gotta love the IT industry.

100
Views
0
Helpful
2
Replies
CreatePlease to create content