Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Suddenly receiving IP_SPOOF Violations in XG 210 from allowed source

Hello:

Yesterday I started seeing these IP_SPOOF violations from our remote site that is on the allowed list in the DNAT firewall rule. They are unable to connect or ping our DNAT devices setup behind the firewall. We can connect to them with out any problem. This happened after the latest update to the firewall (SFOS 20.0.2 MR-2-Build378). I have rebooted both firewalls (in Active-Passive cluster) as well as the switch that connects them. I have also rebooted to router that handles the external public IP addressing. I have never seen this before. Does anyone have any thought?

Thank you



Edited TAGs
[edited by: Erick Jan at 2:27 PM (GMT -7) on 27 Aug 2024]
Parents
  • Hi, Sanket:

    Thanks for the reply. There is a UniFi switch that sits between the two firewalls.

    Port 2, 4 and 5 on each firewall connects to the switch and the switch connects to the individual routers (Sprint, ATT, Comcast). The requests are being seen by all the ports but it should only go to port to as that is how the rule is setup in DNAT. 

Reply
  • Hi, Sanket:

    Thanks for the reply. There is a UniFi switch that sits between the two firewalls.

    Port 2, 4 and 5 on each firewall connects to the switch and the switch connects to the individual routers (Sprint, ATT, Comcast). The requests are being seen by all the ports but it should only go to port to as that is how the rule is setup in DNAT. 

Children