<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Understanding a scenario where TMG drops the packet as spoofed even when the source IP doesn’t belong to the internal network</title><link>http://blogs.technet.com/b/isablog/archive/2010/08/18/understanding-a-scenario-where-tmg-drops-the-packet-as-spoofed-even-when-the-source-ip-doesn-t-belong-to-the-internal-network.aspx</link><description>1. Introduction The core TMG behavior (which is the same on ISA) for handling spoofed packets is well known. Basically, if the IP address belongs to the internal network and it is received on the external interface, it is expected that the packet will</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Understanding a scenario where TMG drops the packet as spoofed even when the source IP doesn’t belong to the internal network</title><link>http://blogs.technet.com/b/isablog/archive/2010/08/18/understanding-a-scenario-where-tmg-drops-the-packet-as-spoofed-even-when-the-source-ip-doesn-t-belong-to-the-internal-network.aspx#3572584</link><pubDate>Tue, 14 May 2013 14:49:20 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3572584</guid><dc:creator>Adedamola Ibironke</dc:creator><description>&lt;p&gt;I had a similar issue, just created the new route and designated the gateway on the LAN card and that was it.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3572584" width="1" height="1"&gt;</description></item><item><title>re: Understanding a scenario where TMG drops the packet as spoofed even when the source IP doesn’t belong to the internal network</title><link>http://blogs.technet.com/b/isablog/archive/2010/08/18/understanding-a-scenario-where-tmg-drops-the-packet-as-spoofed-even-when-the-source-ip-doesn-t-belong-to-the-internal-network.aspx#3556503</link><pubDate>Tue, 05 Mar 2013 13:23:23 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3556503</guid><dc:creator>MaxMVP</dc:creator><description>&lt;p&gt;I confirm Nik&amp;#39;s case&lt;/p&gt;
&lt;p&gt;Our TMG has the default gateway address on the external network interface, and the route for external network as well, but this issue is still pops up.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3556503" width="1" height="1"&gt;</description></item><item><title>re: Understanding a scenario where TMG drops the packet as spoofed even when the source IP doesn’t belong to the internal network</title><link>http://blogs.technet.com/b/isablog/archive/2010/08/18/understanding-a-scenario-where-tmg-drops-the-packet-as-spoofed-even-when-the-source-ip-doesn-t-belong-to-the-internal-network.aspx#3498341</link><pubDate>Wed, 16 May 2012 16:47:27 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3498341</guid><dc:creator>Rajkumar</dc:creator><description>&lt;p&gt;Hi Ori Yosefi,&lt;/p&gt;
&lt;p&gt;We are using TMG 2010 with exchange server 2003. Could you please help me to know how can I stop spoofing using TMG&lt;/p&gt;
&lt;p&gt;Email flow - External Email -&amp;gt; TMG 2010 -&amp;gt; Message Labs -&amp;gt; Exchange Server 2003&lt;/p&gt;
&lt;p&gt;One of the mailbox is keep on receiving NDR from Postmaster stating the email is not delivered for the emails which was not sent by user. while investigating in Message Labs it says the emails are from TMG to Message Labs having from address as internal user and email sent to external invalid email addresses. Not sure how to find the source IP which is relaying those spoofing emails.&lt;/p&gt;
&lt;p&gt;How to identify the external source which is sending these kind of emails and how to stop it. Please advice.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3498341" width="1" height="1"&gt;</description></item><item><title>re: Understanding a scenario where TMG drops the packet as spoofed even when the source IP doesn’t belong to the internal network</title><link>http://blogs.technet.com/b/isablog/archive/2010/08/18/understanding-a-scenario-where-tmg-drops-the-packet-as-spoofed-even-when-the-source-ip-doesn-t-belong-to-the-internal-network.aspx#3488666</link><pubDate>Mon, 26 Mar 2012 19:41:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3488666</guid><dc:creator>bala</dc:creator><description>&lt;p&gt;Thanks, does this applies also for internal scenario?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3488666" width="1" height="1"&gt;</description></item><item><title>re: Understanding a scenario where TMG drops the packet as spoofed even when the source IP doesn’t belong to the internal network</title><link>http://blogs.technet.com/b/isablog/archive/2010/08/18/understanding-a-scenario-where-tmg-drops-the-packet-as-spoofed-even-when-the-source-ip-doesn-t-belong-to-the-internal-network.aspx#3475216</link><pubDate>Thu, 12 Jan 2012 21:04:22 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3475216</guid><dc:creator>Di</dc:creator><description>&lt;p&gt;tnx a LOT!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3475216" width="1" height="1"&gt;</description></item><item><title>re: Understanding a scenario where TMG drops the packet as spoofed even when the source IP doesn’t belong to the internal network</title><link>http://blogs.technet.com/b/isablog/archive/2010/08/18/understanding-a-scenario-where-tmg-drops-the-packet-as-spoofed-even-when-the-source-ip-doesn-t-belong-to-the-internal-network.aspx#3474349</link><pubDate>Sat, 07 Jan 2012 02:18:54 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3474349</guid><dc:creator>Nik</dc:creator><description>&lt;p&gt;Hi, this doesn&amp;#39;t work in my environment. I already have default gateway on my external adapter.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3474349" width="1" height="1"&gt;</description></item><item><title>re: Understanding a scenario where TMG drops the packet as spoofed even when the source IP doesn’t belong to the internal network</title><link>http://blogs.technet.com/b/isablog/archive/2010/08/18/understanding-a-scenario-where-tmg-drops-the-packet-as-spoofed-even-when-the-source-ip-doesn-t-belong-to-the-internal-network.aspx#3351691</link><pubDate>Wed, 25 Aug 2010 00:30:09 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3351691</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;Is there a common scenario that will not have default gateway in the external card?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3351691" width="1" height="1"&gt;</description></item></channel></rss>