Tools
Kiwi Syslog Server NG: Spoof Network Packet forwarding may fail in AWS or other cloud environments
First published date
Last published date
Overview
The Spoof Network Packet option may not work when Kiwi Syslog Server NG is deployed in AWS or another cloud environment. Cloud-provider anti-spoofing controls may block packets whose source address is not assigned to the cloud instance.
Product section
Cause
Spoofed forwarding requires Kiwi Syslog Server NG to send a UDP packet that appears to originate from the original device. Cloud providers may reject this traffic because the source IP address does not belong to the cloud instance or its network interface.
Resolution
-
Verify that the following prerequisites are met:
-
Configure the forwarding action:
-
Capture traffic on the destination side with Wireshark and verify whether the spoofed UDP packets arrive with the expected source address.
-
If the cloud provider blocks spoofed source addresses, clear Spoof Network Packet and use standard UDP forwarding instead. The destination will receive the messages from the Kiwi Syslog Server NG instance rather than from the original sender.
NOTE: Spoofed forwarding is dependent on the cloud provider’s network policies. SolarWinds cannot guarantee that spoofed packets will be accepted in every cloud environment.