Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Tracking a Spoofed IP

Hi all,

Currently I am having an issue with a host on the private MPLS network who is attempting to setup connections to random hosts on port 445. This host is using a spoofed IP address to do the work, and it doesn't seem that he is sequentially moving through the IP ranges. I have engaged our service provider to see if they can help track the host over the MPLS.

So far, I have not been able to find a reliable way to find this host. I have a network tool spanning our main MPLS pipe into our Data Center, and I can see that some hosts are attempting to reply, but the spoofed IP is not a routable address on our network. Therefore this host is not replicating itself, but instead just cause alarms to go off and the increase in resources to move these packets through.

Anyone have any ideas on how to track this host to a certain area?

Cisco Employee

Re: Tracking a Spoofed IP

Have a ACE rule that matches on the port 445 and have it log.

Send the logs to a syslogs server and monitor those. These logs should point you to that host real time.

I hope it helps.


CreatePlease login to create content