IP Spoofing detected

Hello,
I get a lot of messages that ip spoofing is detected.

Process: firewall
Message: IP spoofing: Traffic detected from 0.0.0.0 to 255.255.255.255.

What is the problem here?

Comments

  • 0.0.0.0 is not defined in your config - so the software considers a packet with this source IP addr to be a spoofed packet.

    Some device is sending out these broadcast packets.
    Your full log message should indicate the interface that these are seen on.

Sign In to comment.