Session Report
Summary:
Test run at: 2016-02-10 01:47:39 GMT
Client Prefix (v4): 199.187.218.x/24
Client AS (v4): 19230 (NANOG)
IPv4 Probes: 87
Client Prefix (v6): 2620:0:cxx::/40
Client AS (v6): 19230 (NANOG)
IPv6 Probes: 19
Outbound spoofing summary (from the client to our server) |
Source address type |
IPv4 | IPv6 |
Private -
RFC1918 or ULA |
✔ | blocked | blocked |
Routable |
blocked | blocked |
Largest spoofable neighbor prefix length |
none | none |
Spoof status key |
---|
received | Spoofed packet was received. | ✔ | Pattern of tests from this IP block indicates a switch from allowing spoofing to blocking it. |
rewritten | Spoofed packet was received, but the source address was changed en route. |
blocked | Spoofed packet was not received, but unspoofed packet was. |
unknown | Neither spoofed nor unspoofed packet was received. |
IPv4 Adjacent Netblock Testing:
Your host (199.187.218.x/24) can spoof 0 neighboring addresses
Spoofed source address (anon) | Prefix Length | ASN of spoofed source address | Received |
199.187.218.x/24 | /31 | 19230 | sendto |
199.187.218.x/24 | /30 | 19230 | sendto |
199.187.218.x/24 | /29 | 19230 | sendto |
199.187.218.x/24 | /28 | 19230 | sendto |
199.187.218.x/24 | /27 | 19230 | sendto |
199.187.218.x/24 | /26 | 19230 | sendto |
199.187.218.x/24 | /25 | 19230 | sendto |
199.187.218.x/24 | /24 | 19230 | sendto |
199.187.219.x/24 | /23 | 19230 | sendto |
199.187.216.x/24 | /22 | 19230 | sendto |
199.187.222.x/24 | /21 | 19230 | sendto |
199.187.210.x/24 | /20 | 46562 | sendto |
199.187.202.x/24 | /19 | 19331 | sendto |
199.187.250.x/24 | /18 | 19201 | sendto |
199.187.154.x/24 | /17 | 14330 | sendto |
199.187.90.x/24 | /16 | UNROUTED | sendto |
199.186.218.x/24 | /15 | 7018 | sendto |
199.185.218.x/24 | /14 | UNROUTED | sendto |
199.191.218.x/24 | /13 | UNROUTED | sendto |
199.179.218.x/24 | /12 | UNROUTED | sendto |
199.171.218.x/24 | /11 | 701 | sendto |
199.155.218.x/24 | /10 | 4152 | sendto |
199.251.218.x/24 | /9 | 721 | sendto |
199.59.218.x/24 | /8 | 36056 | sendto |
Meaning of status in Received column:
sendto | The spoofer client was unable to send spoofed headers due to an operating system restriction. |
IPv4 Outbound Filtering Depth:
The tracefilter test found your host
unable to spoof routable, non-adjacent source addresses through
even the first IP hop.
IPv6 probes:
Spoofed source address | Destination | Received
|
---|
2001:4978:1fb:6400::d2 | 2001:48d0:101:501::247 | no |
2001:49aa:111:aa00::11 | 2001:48d0:101:501::247 | no |
fe80:1111::11 | 2001:48d0:101:501::247 | no |
2001:4978:1fb:6400::d2 | 2001:500:4:12::140 | no |
2001:49aa:111:aa00::11 | 2001:500:4:12::140 | no |
fe80:1111::11 | 2001:500:4:12::140 | no |
2001:4978:1fb:6400::d2 | 2001:610:510:115:192:42:115:98 | no |
2001:49aa:111:aa00::11 | 2001:610:510:115:192:42:115:98 | no |
fe80:1111::11 | 2001:610:510:115:192:42:115:98 | no |
2001:4978:1fb:6400::d2 | 2001:770:18:7:225:90ff:fe0c:acb4 | no |
2001:49aa:111:aa00::11 | 2001:770:18:7:225:90ff:fe0c:acb4 | no |
fe80:1111::11 | 2001:770:18:7:225:90ff:fe0c:acb4 | no |
Summary:
The results from all tests are aggregated to produce a summary
"State of IP Spoofing" report.
Feedback:
We welcome questions and feedback to the Spoofer Information Mailing List
and invite users to join the Spoofer
Users Mailing List for discussion and announcements.