<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Topology defined by routes limitation? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Topology-defined-by-routes-limitation/m-p/116746#M16479</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;R80.40 environment.&lt;/P&gt;&lt;P&gt;I have one network 10.10.48.0/20 statically routed to a DMZ. A (more) specific subnet (10.10.60.0/24) from this network is routed to the external Interface.&lt;/P&gt;&lt;P&gt;Most of the other interfaces topology are defined by an object group.&lt;/P&gt;&lt;P&gt;Return packages from to the external interface are dropped by anti spoofing.&lt;/P&gt;&lt;P&gt;Is this an expected behavior, like no splitting of the /20 takes place internally?&lt;/P&gt;&lt;P&gt;Overall I wonder how topology information ist merged and processed when one has multiple route information sources, like defined by routes, objects and interfaces.&lt;/P&gt;&lt;P&gt;Anyway fix for the above was a group with exclusion, but for me it was a bit of an unexpected behavior, that's why I'm asking.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Christoph&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 24 Apr 2021 11:04:13 GMT</pubDate>
    <dc:creator>Christoph</dc:creator>
    <dc:date>2021-04-24T11:04:13Z</dc:date>
    <item>
      <title>Topology defined by routes limitation?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Topology-defined-by-routes-limitation/m-p/116746#M16479</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;R80.40 environment.&lt;/P&gt;&lt;P&gt;I have one network 10.10.48.0/20 statically routed to a DMZ. A (more) specific subnet (10.10.60.0/24) from this network is routed to the external Interface.&lt;/P&gt;&lt;P&gt;Most of the other interfaces topology are defined by an object group.&lt;/P&gt;&lt;P&gt;Return packages from to the external interface are dropped by anti spoofing.&lt;/P&gt;&lt;P&gt;Is this an expected behavior, like no splitting of the /20 takes place internally?&lt;/P&gt;&lt;P&gt;Overall I wonder how topology information ist merged and processed when one has multiple route information sources, like defined by routes, objects and interfaces.&lt;/P&gt;&lt;P&gt;Anyway fix for the above was a group with exclusion, but for me it was a bit of an unexpected behavior, that's why I'm asking.&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Christoph&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Apr 2021 11:04:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Topology-defined-by-routes-limitation/m-p/116746#M16479</guid>
      <dc:creator>Christoph</dc:creator>
      <dc:date>2021-04-24T11:04:13Z</dc:date>
    </item>
    <item>
      <title>Re: Topology defined by routes limitation?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Topology-defined-by-routes-limitation/m-p/116747#M16480</link>
      <description>&lt;P&gt;It’s possible this is a limitation similar to the fact we don’t take into account route priorities.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Apr 2021 16:34:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Topology-defined-by-routes-limitation/m-p/116747#M16480</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-24T16:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: Topology defined by routes limitation?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Topology-defined-by-routes-limitation/m-p/117005#M16504</link>
      <description>&lt;P&gt;PhoneBoy is right, unfortunately.&lt;/P&gt;
&lt;P&gt;There was a discussion about this topic about a year ago (initiated by me):&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Security-Flaw-in-Dynamic-Anti-Spoofing-R80-20-and-above/m-p/89035" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Security-Flaw-in-Dynamic-Anti-Spoofing-R80-20-and-above/m-p/89035&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Unfortunatly, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/2480"&gt;@Meital_Natanson&lt;/a&gt; told us, they do not want to fix that and call it expected behavior.&lt;/P&gt;
&lt;P&gt;Bad decision from my point of view, there is even a "Best current practice" RFC#3704 from 2004 for that.&lt;/P&gt;
&lt;P&gt;Like another Checkmates member said in the thread linked above:&lt;/P&gt;
&lt;P&gt;"It would be great if Check Point made plans to follow the RFC, rather than a loose interpretation of it" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 09:40:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Topology-defined-by-routes-limitation/m-p/117005#M16504</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-04-27T09:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: Topology defined by routes limitation?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Topology-defined-by-routes-limitation/m-p/117011#M16505</link>
      <description>&lt;P&gt;Thank you both of you. I checked your thread. From my (maybe naive) point of view, if there is an option in the UI, my general expectation is, it should also cover edge cases, as long as I can configure them, like in this case click a button. Other than that there should be a big warning sign, that this only works in certain environments.&lt;/P&gt;&lt;P&gt;Same with the new custom vpn topologies, that do some weird network calculations.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 10:23:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Topology-defined-by-routes-limitation/m-p/117011#M16505</guid>
      <dc:creator>Christoph</dc:creator>
      <dc:date>2021-04-27T10:23:20Z</dc:date>
    </item>
  </channel>
</rss>

