I am keep getting this messege from IDS-4235

I am keep getting this error from IDS 4235  with high alert.
Ip Localhost source spoof



VIJAY2766Asked:
Who is Participating?
 
Hugh FraserConnect With a Mentor ConsultantCommented:
The alert indicates the firewall's seen traffic with a source address of 127.x.x.x. Usually, this is someone trying to exploit local host rules on the firewall.

The firewall's correctly blocking the traffic. If it's appearing on an internal interface, you should check the MAC address and track down the culprit.

If it's happening on the external interface, you should pass this info on to your ISP, since they shouldn't be routing this traffic to you.

If it's happening on a wireless interface, lock down access (WPA2). If that's already done and you're using a pre-shared key, it's been compromised.

In all cases, the firewall's doing its thing and blocking the traffic.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.