Solved

Dell Sonicwall - IP Spoof Detection

Posted on 2014-11-17
1
806 Views
Last Modified: 2016-11-23
The Setup:
Sonicwall NSA 4500
X0 LAN
X1 ISP#1
X2 ISP#2
X3 SAN network
X4 ISP #3
x5 ISP #5

X1-2 are actually the same ISP, but just have a disjoint subnet with static IP's in compeltely different ranges.  These two interfaces connect to a small switch and up to the ISP (radio based)

x5 ISP #4 is business class cable for browsing the internet.  No static IPs.

X4 ISP #3 - New ISP via fiber with a ton of static IP's.  

Here's my issue.   Only on the new X4 (ISP #3) - Any time I setup a NAT (either 1-2-1 or port based) and my firewall rules, nothing works.  Went as far as directly attaching a laptop to the carrier's handoff and assigning a static IP and it works.  

After some looking around, I am getting
Intrusion prevention    IP Spoof Dropped   <source> <destiantion>  mac: <MAC of the carriers router>


I can resolve this by turning off IP spoof detection on the "hidden" daiag page - but I'd really a)Not like to have to do that b) Have this work as planned.  

Thoughts?
0
Comment
Question by:JamesonJendreas
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 25

Accepted Solution

by:
Diverse IT earned 500 total points
ID: 40480147
Hi JamesonJendreas,

Exclude the MAC addresses in IPS under Configure IPS Settings.

1. Create Address Objects

First create an Address Objects for each MAC address of the carriers router.

2. Create Address Object Group

Then create an Address Object Group named e.g. IPS Exclusion List and add the Address Objects to that group.

3. Configure IPS Services

Next go to Security Services > IPS and click Configure IPS Settings. Check Enable IPS Exclusion List and select Use Address Objects. Finally, select the newly created Address Object Group named e.g. IPS Exclusion List and click OK to save.
Let me know if you have any questions!
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Node.js 11 82
how to specify windows account to use for connection manager in SSIS package 25 82
Windows 10 Sound Driver Issue 26 62
Windows 2016 Server and Updates 5 45
Is your computer hacked? learn how to detect and delete malware in your PC
I had an issue with InstallShield not being able to use Computer Browser service on Windows Server 2012. Here is the solution I found.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question