Bugzilla – Bug 11464
IP Spoof From Boom
Last modified: 2009-09-22 08:25:48 UTC
One of my two SqueezeBox Booms is constantly generating an IP Spoof warning message from my internal SonicWALL firewall. Here is the relevant information from the Boom: Player Model: boom Firmware: 43 Player IP Address: 172.20.201.13 Player MAC Address: 00:04:20:1e:0e:57 And here is the relevant information from the SonicWALL: 03/25/2009 06:36:08.000 - Alert - Intrusion Prevention - IP spoof dropped - 169.254.17.125, 138, X0 - 169.254.255.255, 138, X1 - MAC address: 00:04:20:1e:0e:57 Not that the MAC addresses match. The Boom already has a DHCP address. It shouldn't be sending out any packets on any other address. I have tried powering the Boom off and back on.
Craig: which model (FW version) of the SonicWall do you have?
I have a SonicWALL NSA 4500, running SonicOS Enhanced 5.2.0.1-21o.
Please try the following: Factory reset the Boom Reconnect to your network Wired / Wireless Does the same error happen with both connection types? Do you have another Boom on your network, or just the one?
I will try a factory reset later today. In the meantime, I can verify that the spoof happens every 24-25 minutes. I am running 2 booms, both wired. (No wireless.)
(In reply to comment #4) > I am running 2 booms, both wired. (No wireless.) Do they both have this same issue or only 0e:57 ?
Just 0e:57 has the issue, at least so far. (Although the other Boom was only installed about two weeks ago.)
I factory reset the boom and re-entered the wired network information. After about 25 minutes, the IP spoof is back. (No change in behavior....)
Could be related to bug 11078.
Since there's now a planned 7.3.3 release, bugs which won't make the cut-off are being moved to the next target out. If you feel that this bug needs to be addressed more (or less) urgently than the 7.4 release, please cc chris@slimdevices.com and leave a comment in the bug to that effect so we can review it. Thanks.