<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Antispoofing with dynamic routing in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Antispoofing-with-dynamic-routing/m-p/138887#M21152</link>
    <description>&lt;P&gt;Yes network defined by routes will work fine, the routing table is checked for updates every 1 second and the topology updated accordingly based on this setting:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="update.png" style="width: 695px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14949iDB778C9A55FB649D/image-size/large?v=v2&amp;amp;px=999" role="button" title="update.png" alt="update.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jan 2022 13:02:45 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2022-01-19T13:02:45Z</dc:date>
    <item>
      <title>Antispoofing with dynamic routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Antispoofing-with-dynamic-routing/m-p/138800#M21115</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For antispoofing config (on R80.30 and R81.10), is it fine to be internal &amp;gt; defined by routes on the OSPF/BGP interfaces?&amp;nbsp; Do routing changes take effect immediately in terms of the antispoofing checks or does it recalculate every X amount of time etc?&amp;nbsp; Any gotcha that we should be aware of?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 01:47:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Antispoofing-with-dynamic-routing/m-p/138800#M21115</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2022-01-19T01:47:23Z</dc:date>
    </item>
    <item>
      <title>Re: Antispoofing with dynamic routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Antispoofing-with-dynamic-routing/m-p/138804#M21119</link>
      <description>&lt;P&gt;That is exactly how you should have it. I did that for 2 customers and works fine for more than a year now, no issues. For your reference, below is from Smart console doc and this applies literally to any R80+ version:&lt;/P&gt;
&lt;UL class="listbullet2"&gt;
&lt;LI class="listbullet2"&gt;&lt;STRONG class="menuoptions"&gt;Network defined by routes&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The gateway dynamically calculates the topology behind this interface. If the network changes, there is no need to click "Get Interfaces" and install a policy.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.20/SmartConsole_OLH/EN/html_frameset.htm?topic=documents/R80.20/SmartConsole_OLH/EN/ZvkmnUK_XluBBIIAw1mF3A2" target="_self"&gt;R80.20 smart console guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 03:10:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Antispoofing-with-dynamic-routing/m-p/138804#M21119</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-01-19T03:10:06Z</dc:date>
    </item>
    <item>
      <title>Re: Antispoofing with dynamic routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Antispoofing-with-dynamic-routing/m-p/138887#M21152</link>
      <description>&lt;P&gt;Yes network defined by routes will work fine, the routing table is checked for updates every 1 second and the topology updated accordingly based on this setting:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="update.png" style="width: 695px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14949iDB778C9A55FB649D/image-size/large?v=v2&amp;amp;px=999" role="button" title="update.png" alt="update.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jan 2022 13:02:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Antispoofing-with-dynamic-routing/m-p/138887#M21152</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-01-19T13:02:45Z</dc:date>
    </item>
    <item>
      <title>Re: Antispoofing with dynamic routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Antispoofing-with-dynamic-routing/m-p/139271#M21248</link>
      <description>&lt;P&gt;If you have overlapping routes, you should read my post here:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Security-Flaw-in-Dynamic-Anti-Spoofing-R80-20-and-above/m-p/89035#M11057" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Security-Flaw-in-Dynamic-Anti-Spoofing-R80-20-and-above/m-p/89035#M11057&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Summary: Check Points implementation of "Antispoofing defined by routes" does not follow the RfC or the normal routing logic (most specific route is taken). It will not block anything needed, but allows more than needed.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 14:43:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Antispoofing-with-dynamic-routing/m-p/139271#M21248</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2022-01-24T14:43:27Z</dc:date>
    </item>
  </channel>
</rss>

