<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CLI Anti-Spoofing Information in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15659#M1108</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes - I know it can be done in the GUI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to know if anyone has found a way to check it on the local gateway.&amp;nbsp; The GUI is currently very time consuming to audit, but scripting to gateways is very simple.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm guessing since its part of the policy, it won't be super easy to find on the local gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Dec 2017 14:56:44 GMT</pubDate>
    <dc:creator>Bryce_Myers</dc:creator>
    <dc:date>2017-12-01T14:56:44Z</dc:date>
    <item>
      <title>CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15655#M1104</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone know of a way to see your anti-spoofing configuration per interface on the CLI?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61158_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically --&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Anti-Spoofing is Enabled (y/n)&lt;/LI&gt;&lt;LI&gt;Anti-Spoofing Action (Detect/Prevent)&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Nov 2017 19:34:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15655#M1104</guid>
      <dc:creator>Bryce_Myers</dc:creator>
      <dc:date>2017-11-30T19:34:46Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15656#M1105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello for each interface in the topology you can set the anti-spoofing.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/61171_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Dec 2017 14:28:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15656#M1105</guid>
      <dc:creator>Pablo_Barriga</dc:creator>
      <dc:date>2017-12-01T14:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15657#M1106</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Firewall CLI or R80+ SMS CLI?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My Book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; Second Edition Coming Soon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Dec 2017 14:50:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15657#M1106</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-12-01T14:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15658#M1107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Firewall CLI at the moment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Dec 2017 14:55:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15658#M1107</guid>
      <dc:creator>Bryce_Myers</dc:creator>
      <dc:date>2017-12-01T14:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15659#M1108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes - I know it can be done in the GUI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to know if anyone has found a way to check it on the local gateway.&amp;nbsp; The GUI is currently very time consuming to audit, but scripting to gateways is very simple.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm guessing since its part of the policy, it won't be super easy to find on the local gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Dec 2017 14:56:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15659#M1108</guid>
      <dc:creator>Bryce_Myers</dc:creator>
      <dc:date>2017-12-01T14:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15660#M1109</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think there is an opportunity to leverage GUIDBedit from the management CLI to look at the policy, but even if its changed in the policy - if it hasn't been deployed, the gateway doesn't actually have the anti-spoofing settings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Dec 2017 15:09:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15660#M1109</guid>
      <dc:creator>Bryce_Myers</dc:creator>
      <dc:date>2017-12-01T15:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15661#M1110</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bryce I think this info should be useful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;EM style="border: 0px; font-weight: inherit;"&gt;fw ctl set int fw_antispoofing_enabled 0&lt;/EM&gt;&lt;BR /&gt;&lt;EM style="border: 0px; font-weight: inherit;"&gt;sim feature anti_spoofing off ; fwaccel off ; fwaccel on&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;EM style="border: 0px; font-weight: inherit;"&gt;fw ctl set int fw_antispoofing_enabled 1&lt;/EM&gt;&lt;BR /&gt;&lt;EM style="border: 0px; font-weight: inherit;"&gt;sim feature anti_spoofing on ; fwaccel off ; fwaccel on&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;EM style="border: 0px; font-weight: inherit;"&gt;This was posted on the&amp;nbsp;&lt;A href="https://community.checkpoint.com/thread/5319-my-top-3-check-point-cli-commands" target="_blank"&gt;https://community.checkpoint.com/thread/5319-my-top-3-check-point-cli-commands&lt;/A&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:05:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15661#M1110</guid>
      <dc:creator>Pablo_Barriga</dc:creator>
      <dc:date>2019-06-21T09:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15662#M1111</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Isn't that just a global anti-spoofing setting?&amp;nbsp; I can't tell what the configuration per interface is.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Dec 2017 15:39:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15662#M1111</guid>
      <dc:creator>Bryce_Myers</dc:creator>
      <dc:date>2017-12-01T15:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15663#M1112</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think there is a direct way to pull this info from the running firewall kernel (I originally thought it could be provided by the &lt;STRONG&gt;sim ranges&lt;/STRONG&gt; command), but what you can do is first run &lt;STRONG&gt;fw ctl iflist&lt;/STRONG&gt; on the firewall to get the list of interfaces, and then view (not edit!) the firewall's $FWDIR/state/local/FW1/local.set file.&amp;nbsp; In that file you will find a section called "if_info" and under that "objtype (gw)" and then an indented list of firewall interfaces.&amp;nbsp; Under each firewall interface you will see two values:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;has_addr_info (true|false)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; true: antispoofing enabled on that interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; false: antispoofing is disabled on that interface&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;monitor_only (true|false)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; true: antispoofing action is Detect on that interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; false: antispoofing action is Prevent on that interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm sure someone could script something to pull this info out of the file a bit easier...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My Book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; Second Edition Coming Soon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Dec 2017 00:45:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15663#M1112</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-12-02T00:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15664#M1113</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tim - this is great information!&amp;nbsp; I'm going to build a script to check for these settings on the gateway.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Dec 2017 20:07:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15664#M1113</guid>
      <dc:creator>Bryce_Myers</dc:creator>
      <dc:date>2017-12-02T20:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15665#M1114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looking on my R80.10 gateway, for each interface, I also see interface_topology which tells you what subnets are "valid" on a given interface (assuming that's useful to your task).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Dec 2017 16:43:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15665#M1114</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-12-03T16:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15666#M1115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yep that same $FWDIR/state/local/FW1/local.set on the firewall does show the calculated network topology for each interface as well as the anti-spoofing settings.&amp;nbsp; Could definitely be handy if there are lots of nested groups specified in the anti-spoofing settings that makes figuring out the actual topology (and resulting anti-spoofing enforcement) difficult from the SmartDashboard/SmartConsole.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; My Book "Max Power: Check Point Firewall Performance Optimization" &lt;BR /&gt; Second Edition Coming Soon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Dec 2017 15:17:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15666#M1115</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2017-12-04T15:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15667#M1116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Look at this article:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2990"&gt;Show Address Spoofing Networks via CLI &lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Heiko&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2018 12:36:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15667#M1116</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-06-25T12:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: CLI Anti-Spoofing Information</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15668#M1117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Pablo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can we disable anti spoofing from command line in R80.20?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In R80.20 GA the following command has been removed:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;sim feature anti_spoofing off&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@pa:0]# sim feature anti_spoofing off&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Command 'sim feature' has been replaced. Use 'fwaccel feature' instead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Expert@pa:0]# fwaccel feature anti_spoofing off&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Invalid feature 'anti_spoofing'&lt;BR /&gt;Usage: fwaccel feature &amp;lt;name&amp;gt; {on|off|get}&lt;/P&gt;&lt;P&gt;Available features: sctp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Kris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Oct 2018 12:44:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CLI-Anti-Spoofing-Information/m-p/15668#M1117</guid>
      <dc:creator>Kris_Pellens</dc:creator>
      <dc:date>2018-10-08T12:44:08Z</dc:date>
    </item>
  </channel>
</rss>

