Mailing List Archive

Curious Logs in my DMZ
Hello list,

sorry for my english...

Given:
A collapsed (CheckPoint 4.1) firewall (-cluster) with a dmz (1 Interface to
a switch and some server).
On one server (only 1 interface) runs ntop v1.3.2 on suse 7.1 .

In Data Received / Protocols, i see AppleTalk and IPX from unknown (Router?)
MAC.
In this network, i should only find the firewall and the DMZ-Server as MAC
addresses!?!

In Data Received / IP, i see NFS from internal (Windows!) Workstations. ???

There are no (implicit) rules for these ip/protocols on my firewall.

Any explanations?

Greetings,
Mathias Preusse