I am currently running a Sonicwall firewall and have over the past week recieved a few IP Spoof detected warnings. The warning shows an IP address that could be on my subnet, but falls outside my current scope. The warning gives me a MAC address as well, and though the spoof seems to come from different IP addresses each time, the MAC remains the same. I am fairly new in the security realm and really have no idea what this warning means or if some one is actaully attempting illicit activity.
Off topic - I am also getting pinged 4-5 times per minute from addressed fairly similar to my public IP. I have called the ISP with ni results. I am thinking this is a product of the Blaster worm. Anyone else seeing this type of traffic.
Thanks for any info provided.




Reply With Quote