mdamores Lv3Posted 27 Dec 2023 11:54
  
seems like you are experiencing Network Spoofing or Network Gateway Anti-Bypass attach from your internal network. Below are some of the steps to help you identify the MAC address and trace the source of the attack.

1. Check the logs on your firewall and look for any suspicious activities. Inspect as well the logs of the affected VMs for any unusual or unauthorized activities
2. Use network monitoring tools like wireshark to capture and analyze network traffic from there you may look for patterns that might indicate attack.
3. check the ARP tables on your network devices to show the mapping between IP addresses and MAC addresses. Try using the "arp" command on Linux to view ARP table
4. review firewall rules to see any rules that might allow unauthorized access.
5. Check alerts from your IDS, if you have any
6. isolate affected systems to avoid further damage
7. investigate your Lunux VMs and check all the running processes, network connectivity, and any unusual configurations
8. change login credentials

I Can Help:

Change

Moderator on This Board

0
2
4

Started Topics

Followers

Follow

67
14
3

Started Topics

Followers

Follow

3
0
2

Started Topics

Followers

Follow

1
131
3

Started Topics

Followers

Follow

Board Leaders