Able to see other peoples traffic on Comcast

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Able to see other peoples traffic on Comcast

L1 Bithead

Is there anyone else that has Comcast Fiber circuits that is able to see other people's traffic on the public interface?

We have been POC'ing the DNS Security License on several FW's once we turned  it on we are seeing a large amount of DNS Tunneling alerts coming into XDR.  When we investigate they are coming from the Untrust network on the default intrazone rule.  

 

After looking further into this it is on our sites that have Comcast Fiber circuits.  When we look at our intrazone traffic from Untrust, we are seeing traffic that is either src or dst from another Comcast network that is not on our segment.  When we filter down by interface this is only occurring on the comcast interface.  We have multiple circuits at our sites and all the other circuits are showing the expected behavior where the Untrust intrazone traffic only has our IP's in the src/dst.

 

 

 

 

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello,

That is normal when on a common subnet. Its just traffic that the PAN see's as it hits its interface.

Regards,

@OtakarKlier 

Really? Seeing such traffic from other customers is normal? I mean the IPs in the screenshot are not only one small subnet. It also does not look like broadcast traffic for tcp syn packets where arp entries timed out and the firewall was even seeing app-id's and not only 'incomplete'.

L7 Applicator

It is interesting to see the Untrust to Untrust with all of that traffic. 

This is not the dropped traffic, which would probably be more.  But it is hard to say why you are seeing that traffic.. again due to routing.. you are seeing traffic pass thru your Untrust interface.

Is that normal?  hard to say..  It all really depends.. but it sounds like dynamic routes are not as clean as they need to be. 

If you traceroute to those destination IP's, I wonder where they go.

LIVEcommunity team member
Stay Secure,
Joe
Don't forget to Like items if a post is helpful to you!
  • 2228 Views
  • 3 replies
  • 1 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!