MsExchange Blog Spot Telnet25

August 24, 2011

Status: A packet was dropped because Forefront TMG determined that the source IP address is spoofed.

Filed under: General — telnet25 @ 3:04 am


TMG Logging is showing fallowing errors:……………….

  • Denied Connection MCCNPWINTMG1 8/15/2011 11:09:37 PM
  • Log type: Firewall service
  • Status: A packet was dropped because Forefront TMG determined that the source IP address is spoofed.
  • Rule: None – see Result Code
  • Source: Internal (
  • Destination: Local Host (
  • Protocol: RDP (Terminal Services)
  • Additional information
  • Number of bytes sent: 0 Number of bytes received: 0
  • Processing time: 0ms Original Client IP:


The network is reaching out to TMG internal interface is not recognized by the TMG server, thus TMG thinks the IP address is spoofed and drop the connection.

You need to tell TMG the Network or the IP Address itself does belong to Internal Network, so

Add static route to destination , for example

If we want to add static route for IP address , and tell TMG what DGW to use to reach out this IP we would be using fallowing command from elevated command window ( CMD run as an administrator)


route add mask -p

Open MFTMG , click networking, Under Networks

Internal , internal Properties , click add range and add the IP address range.


Once you have completed this Click on monitoring, configuration and click to make sure TMG servers have been synched.

*** Before making any changes as good practice take backup of your TMG as the backup takes couple, minutes and you can go back if there are any unexpected issues, otherwise like me you will sit in the middle of the night and have to re-build everything (-: , un-necessary headache IMO***

**** Also as another good practice make the changes on the ARRAY MANAGER, if you are running TMG array***

Oz Casey, Dedeal ( MVP north America)
MCSE 2003, M+, S+, MCDST
Security+, Project +, Server + (Blog) (Blog)


Leave a Comment »

No comments yet.

RSS feed for comments on this post. TrackBack URI

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out /  Change )

Google+ photo

You are commenting using your Google+ account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

Blog at

%d bloggers like this: