Check Point community forum
May 20, 2012, 10:01:45 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News:
 
  Home   Forum   Help Search Login Register   **
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 20, 2012, 10:01:45 PM

Login with username, password and session length
Pages: [1]
  Print  
Author Topic: BOOTPS (UDP/67) traffic on DMZ interface of Firewall  (Read 916 times)
rockysam39
Newbie
*
Posts: 16


« on: June 26, 2008, 03:15:37 PM »



I have a question about the following dropped packets I see in SmartView Tracker.

Number:                         2715947
Date:                              26Jun2008
Time:                             11:47:56
Product:                         VPN-1 Power/UTM
Interface:                       eth6
Origin:                            UFBEJ10001
Type:                             Log
Action:                            Drop
Protocol:                        udp
Service:                         bootps (67)
Destination:                   bc-255.255.255.255 (255.255.255.255)
Rule:                              7
Current Rule Number:   7-CNFWMarch2008
Source Port:                   bootpc (68)
Rule UID:                       {55E7EB4A-BEBB-4DC9-9CBA-9EF2B7A36055}
Policy Info:                    Policy Name: CNFWMarch2008
                                      Created at: Thu Jun 26 15:30:10 2008
                                      Installed from: SmartCenter-India-1



We see these dropped packets continuously on the eth6 of the Resilience box we have, running NGX R61.

This interface is for the DMZ, which is connected to a Layer 2 Switch (Cisco 2960, not configured yet) and the switch has one Juniper box & 2 DELL servers connected (none of these devices are configured yet).

I shutdown all the devices connected to the L2 Switch but that did not help . I even had all the devices unplugged from the Switch but we still get the dropped packets. I also turned the interface down and then turned it back up but to no effect.

Can anyone please help me understand why its happening. Let me know if you need more information to analyse.

I'm sure something something in the Switch is generating that traffic...can anyone help me understand what that is and how I can stop that traffic?
Logged
juve
Administrator
Jr. Member
*****
Posts: 92


« Reply #1 on: June 30, 2008, 11:24:41 AM »

sniff on the firewall so you can get the mac address. That can help you find out what the source is, using the OUI.
Logged
Pages: [1]
  Print  
 
Jump to:  

Recent
[May 14, 2012, 10:59:10 AM]

[May 14, 2012, 10:58:46 AM]

[May 14, 2012, 10:58:11 AM]

[May 14, 2012, 10:57:18 AM]

[May 14, 2012, 10:56:41 AM]

[May 14, 2012, 10:56:25 AM]

[May 14, 2012, 10:55:41 AM]

[May 14, 2012, 10:55:12 AM]

[May 14, 2012, 10:54:42 AM]

[May 14, 2012, 10:54:10 AM]
Members
Total Members: 246
Latest: balfaszok
Stats
Total Posts: 281
Total Topics: 174
Online Today: 5
Online Ever: 24
(May 19, 2012, 04:16:58 PM)
Users Online
Users: 0
Guests: 9
Total: 9
Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
TinyPortal v0.9.8 © Bloc
Valid XHTML 1.0! Valid CSS!