Hello list,
sorry for my english...
Given:
A collapsed (CheckPoint 4.1) firewall (-cluster) with a dmz (1 Interface to
a switch and some server).
On one server (only 1 interface) runs ntop v1.3.2 on suse 7.1 .
In Data Received / Protocols, i see AppleTalk and IPX from unknown (Router?)
MAC.
In this network, i should only find the firewall and the DMZ-Server as MAC
addresses!?!
In Data Received / IP, i see NFS from internal (Windows!) Workstations. ???
There are no (implicit) rules for these ip/protocols on my firewall.
Any explanations?
Greetings,
Mathias Preusse
sorry for my english...
Given:
A collapsed (CheckPoint 4.1) firewall (-cluster) with a dmz (1 Interface to
a switch and some server).
On one server (only 1 interface) runs ntop v1.3.2 on suse 7.1 .
In Data Received / Protocols, i see AppleTalk and IPX from unknown (Router?)
MAC.
In this network, i should only find the firewall and the DMZ-Server as MAC
addresses!?!
In Data Received / IP, i see NFS from internal (Windows!) Workstations. ???
There are no (implicit) rules for these ip/protocols on my firewall.
Any explanations?
Greetings,
Mathias Preusse