Tools

Kiwi Syslog Server NG: Spoof Network Packet forwarding may fail in AWS or other cloud environments

First published date

10/1/2026 9:40 PM

Last published date

10/1/2026 9:40 PM

Overview

The Spoof Network Packet option may not work when Kiwi Syslog Server NG is deployed in AWS or another cloud environment. Cloud-provider anti-spoofing controls may block packets whose source address is not assigned to the cloud instance.

Product section

Kiwi Syslog Server

Cause

Spoofed forwarding requires Kiwi Syslog Server NG to send a UDP packet that appears to originate from the original device. Cloud providers may reject this traffic because the source IP address does not belong to the cloud instance or its network interface.

Resolution

  1. Verify that the following prerequisites are met:

    • Kiwi Syslog Server NG is licensed.
    • The forwarding protocol is UDP.
    • The destination uses IPv4.
    • Npcap, including the Npcap Loopback Adapter, is installed.
    • A valid network adapter is selected in the forwarding action.
  2. Configure the forwarding action:

    1. Go to Setup > Rules.
    2. Select the applicable rule and click Edit.
    3. Add or edit the Forward to another host action.
    4. Specify the destination host and UDP port.
    5. Select Spoof Network Packet.
    6. Select the appropriate network adapter.
  3. Capture traffic on the destination side with Wireshark and verify whether the spoofed UDP packets arrive with the expected source address.

  4. If the cloud provider blocks spoofed source addresses, clear Spoof Network Packet and use standard UDP forwarding instead. The destination will receive the messages from the Kiwi Syslog Server NG instance rather than from the original sender.

NOTE: Spoofed forwarding is dependent on the cloud provider’s network policies. SolarWinds cannot guarantee that spoofed packets will be accepted in every cloud environment.

Additional Notes

  • The Spoof Network Packet option applies only to UDP forwarding with IPv4 addresses.
  • If spoofed forwarding is unavailable, standard forwarding remains the supported fallback for sending syslog messages to another host.