<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring of Anti-Spoofing traffic in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20247#M1554</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Isnt some stats included in &lt;STRONG&gt;$FWDIR/state/local/FW1/local.set &lt;/STRONG&gt;? How cpview (SecureXL) knows how many packets were dropped because of anti-spoofing ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Aug 2018 21:23:48 GMT</pubDate>
    <dc:creator>JozkoMrkvicka</dc:creator>
    <dc:date>2018-08-20T21:23:48Z</dc:date>
    <item>
      <title>Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20242#M1549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way how to monitor anti-spoofing traffic in R77.30 ? I know that I can choose Alert, Log or None in spoofing properties for specific interface. But does someone know how to send for example syslog event in case gateway recognize spoofing traffic ? Or send mail ...&lt;/P&gt;&lt;P&gt;Searching all logs to found "spoofing" word in Information isnt good approach... There must be something on CLI how to check if interface faced spoofing traffic (as it issue log event towards log server).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for every suggestion in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Aug 2018 09:52:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20242#M1549</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-08-18T09:52:20Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20243#M1550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One place you can see anti-spoofing drop packets (albeit not on a specific interface) is cpview.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69252_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want Alerts to run a script, you can set that in Global Properties (but will apply for anything with Log type set to Alert):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69253_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 18 Aug 2018 15:18:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20243#M1550</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-18T15:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20244#M1551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, I will check that.&lt;/P&gt;&lt;P&gt;What is default path of that UserDefined script? Or can I use full path of script, like: /var/tmp/testing.sh ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Aug 2018 18:56:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20244#M1551</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-08-19T18:56:20Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20245#M1552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use full path.&lt;/P&gt;&lt;P&gt;Offhand I am not sure what the default path is for this screen.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Aug 2018 23:35:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20245#M1552</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-19T23:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20246#M1553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was not managed to get it work &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.checkpoint.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/P&gt;&lt;P&gt;First, I want to test it via specific rule, so I have created new rule with Track: "Alert". My understanding is that the script located in /var/log/test.sh should be executed every time this specific rule is matched.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My settings in Global Properties:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69310_pastedImage_4.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According logs, the specific traffic is matched and I also see Alert in logs. The only problem is that it didnt activate the script.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried to set Track as "UserDefined" and with this setup, the script was executed.&lt;/P&gt;&lt;P&gt;Is there any way how to do the same just for Alert (as in Anti-spoofing in R77.30 there are only following options available):&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69311_pastedImage_5.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Aug 2018 21:03:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20246#M1553</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-08-20T21:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20247#M1554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Isnt some stats included in &lt;STRONG&gt;$FWDIR/state/local/FW1/local.set &lt;/STRONG&gt;? How cpview (SecureXL) knows how many packets were dropped because of anti-spoofing ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Aug 2018 21:23:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20247#M1554</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-08-20T21:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20248#M1555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know both of these things should operate exactly the same.&lt;/P&gt;&lt;P&gt;I would open a TAC case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2018 02:00:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20248#M1555</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-21T02:00:58Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20249#M1556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Look into&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;sk56701, there are some ideas how to make it work. The fact script is not working means there is something wrong with it. Most probably variables.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2018 08:22:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20249#M1556</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-21T08:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20250#M1557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Valeri,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The script is working in case I choose "UserDefined" in Track option for the particular rule.&lt;/P&gt;&lt;P&gt;In case I want to do the same for "Alert", it will not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My script looks like:&lt;/P&gt;&lt;P&gt;&lt;IMG class="j-img-floatstart image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69670_pastedImage_1.png" style="float: left;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My rule looks like (it will not execute script):&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-6 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69690_pastedImage_17.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This rule will execute the script:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-5 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69689_pastedImage_16.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And my Alert settings looks like:&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69673_pastedImage_5.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2018 20:05:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20250#M1557</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-08-21T20:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20251#M1558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch Abernathy&lt;/A&gt;‌ &lt;A href="https://community.checkpoint.com/migrated-users/2138"&gt;Valeri Loukine&lt;/A&gt;‌ issue solved with following configuration of Alerts in Global Properties:&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="69691" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/69691_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So now my final question is:&lt;/P&gt;&lt;P&gt;How can I simulate Address Spoofing for interface&amp;nbsp;eth1.50 with subnet 10.20.30.0/24 to see if this is really working&amp;nbsp;in case I will select Alert in Anti-Spoofing Tracking option ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NOTE: I am running internal LAB in VMware, so I can do (almost) everything&amp;nbsp;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2018 20:23:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20251#M1558</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-08-21T20:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20252#M1559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Create a VM with the desired address and try to ping "through" the firewall?&lt;/P&gt;&lt;P&gt;You'll probably have to muck with the routing/ARP tables to make it work right.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 21 Aug 2018 22:40:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20252#M1559</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-08-21T22:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20253#M1560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;easy, configure anti-spoofing manually and exclude some parts of your network attached to this interface. Link, instead of /24 do less than that.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 22 Aug 2018 08:44:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20253#M1560</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-22T08:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20254#M1561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That must be true. "Run popup alert script" means the binary is under $FWDIR/bin. If it is not, it is qualified as a "User defined alert"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Aug 2018 08:22:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20254#M1561</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-24T08:22:27Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20255#M1562</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jozko,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Was you able to perform this. Even I want to perform anti spoofing lab in vmware. Don't know howto do it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Dec 2018 21:06:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20255#M1562</guid>
      <dc:creator>Rohit_Gandas</dc:creator>
      <dc:date>2018-12-06T21:06:23Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20256#M1563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, I was not able to simulate antispoofing traffic &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 17:08:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20256#M1563</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2018-12-07T17:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring of Anti-Spoofing traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20257#M1564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was able to.&lt;/P&gt;&lt;P&gt;Have a loom at this article i made on anti spoofing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Dec 2018 17:37:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Monitoring-of-Anti-Spoofing-traffic/m-p/20257#M1564</guid>
      <dc:creator>Rohit_Gandas</dc:creator>
      <dc:date>2018-12-07T17:37:08Z</dc:date>
    </item>
  </channel>
</rss>

