User guide

149
Links Bar
Your Netopia Gateway reports the following eight event types:
Event Details
Details on the eight specific event types and the information logged are:
IP Source Address Spoofing. The Gateway checks all incoming packets to see if the
IP address attached is valid for the interface the packet is received through. If the address
of the packet is not valid for the interface the packet is discarded.
Logged information includes:
Source Routing. IP source routing information packets will be received and accepted by
the Netopia Gateway. Logging of this activity is provided in the event the source route infor-
mation has been forged, but appears as valid data.
Logged information includes:
Subnet Broadcast Amplification. Distributed DoS (Denial of Service) attacks often
use a technique known as broadcast amplification, in which the attacker sends packets to
a router’s subnet broadcast address. This causes the router to broadcast the packet to
each host on the subnet. These, in turn, become broadcast sources, thereby involving
many new hosts in the attack. The Netopia unit detects and discards any packets that
IP Source Address Spoofing Source Routing
Subnet Broadcast Amplification Illegal Packet Size (Ping of Death)
Port Scan (TCP/UDP) Excessive Pings
Login Failures MAC Address Spoofing
• IP source address • IP destination address
• Number of attempts • Time at last attempt
• IP interface
• IP source address • IP destination address
• Number of attempts • Time at last attempt
• IP interface