Skip to Content.
Sympa Menu

wg-multicast - SAP address seen from IPM tunnel

Subject: All things related to multicast

List archive

SAP address seen from IPM tunnel


Chronological Thread 
  • From: "John Center" <>
  • To:
  • Subject: SAP address seen from IPM tunnel
  • Date: Tue, 13 Sep 2005 12:18:27 -0400

Hi,

I have a very simple outbound ACL on our I2 interface that prevents someone from our network spoofing other addresses. I have a "deny any log-input" statement to catch what interface the spoofed address is coming from. I've have seen a number of messages logged that look like this:

Sep 13 08:49:48.949 EDT: %SEC-6-IPACCESSLOGP: list OUT-I2-ACCESS denied udp 128.59.31.169(1027) (Tunnel0 ) -> 224.2.127.254(9875), 1 packet

We tunnel our multicast traffic to the campus, but I don't understand why we would see a packet sourced from outside our network to the SAP/SDR address. This is probably something obvious, but not to me... ;-)

An explanation would be greatly appreciated.

Thanks.

-John
--
John Center
Villanova University




Archive powered by MHonArc 2.6.16.

Top of Page