Tools

Spoof Network Packet Option in Kiwi Syslog Server

If you want to retain the original source address you can use the “Spoof Network Packet” option in Kiwi Syslog Server.

First published date

10/19/2018 8:35 PM

Last published date

11/10/2022 10:19 PM

Overview

When you forwarding packets in Kiwi Syslog Server, you can use the “Spoof Network Packet” option if you want to retain the original source IP address.

Product section

Kiwi Syslog Server

Resolution

The network packet will be spoofed to appear as though the fowarded message has come directly from the originating devices' IP address, and not the address of the Syslog Server.  Kiwi Syslog Server will use the Selected Network Adapter to send the spoofed UDP/IP packet.

Note:

  • This feature is only available in the licensed version, and requires Npcap 0.9989 or above
  • This option only applies to syslog messages forwarded via UDP protocol with IPv4 address only.
  • This option only applies to syslog messages forwarded via UDP protocol.
     

Important Note:

  • During the installation of Npcap, ensure that "Legacy Loopback Support" and "Install Npcap in Winpcap API compatible mode" are checked.
  • Npcap can be downloaded at Npcap release archive page (content provided by Gordon Lyon, available at https://npcap.com,  obtained on November 11, 2022)
  • Nmap 7.9x can be downloaded from Nmap.org page (content provided by Gordon Lyon, available at https://nmap.org,  obtained on November 11, 2022)


nmap7.92.jpg
(Screenshots property of © <2022> https://npcap.com/)
loopback.JPG




Note:

  • If Legacy Loopback Support is not available from the Npcap installation, you will need to use the Nmap7.9x setup file to install Npcap with Legacy Loopback Support. This will enable to the "Spoof Network Packet - IPv4 - UDP Only" option on Kiwi Setup. 


Test button:
Use the Test button to send a test Syslog message to the host(s) specified.

Note:  If the "Spoof Network Packet" option is used, then the "Original Address=" tag will not be used.  The Syslog packet will be forwarded to the destination address as though it has been sent from the originating IP address.



Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment. You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.