<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to check the target of source ip / destiantion ip if it is dropped due to AntiSpoofing? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-the-target-of-source-ip-destiantion-ip-if-it-is/m-p/153702#M25820</link>
    <description>&lt;P&gt;Here's a question you might be interested in.&lt;/P&gt;&lt;P&gt;A Checkpoint Gateway is used as Second tier Firewall. Every time we get "Network Topology" data from a Gateway object, Anti Spoofing again becomes active.&lt;/P&gt;&lt;P&gt;&lt;A href="https://futbolred.net/" target="_self"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="futbolred.JPG" style="width: 180px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17291iAAC124B2B60D9441/image-size/medium?v=v2&amp;amp;px=400" role="button" title="futbolred.JPG" alt="futbolred.JPG" /&gt;&lt;/span&gt;&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 24 Jul 2022 18:41:35 GMT</pubDate>
    <dc:creator>cuiko78</dc:creator>
    <dc:date>2022-07-24T18:41:35Z</dc:date>
    <item>
      <title>How to check the target of source ip / destiantion ip if it is dropped due to AntiSpoofing?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-the-target-of-source-ip-destiantion-ip-if-it-is/m-p/153667#M25810</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just find a question here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using the Checkpoint Gateway as Second tier Firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Every time we get "Network Topology" from the Gateway objects, the Anti Spoofing will enable again.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then the internet traffic is dropped due to the Anti-Spoofing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but if we check out the traffic log, seems we just got the "allow" message but not "Drop due to Spoofing..."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BTW, how can we disable the Anti-Spoofing forever?&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 06:59:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-the-target-of-source-ip-destiantion-ip-if-it-is/m-p/153667#M25810</guid>
      <dc:creator>BlueGrass</dc:creator>
      <dc:date>2022-07-23T06:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to check the target of source ip / destiantion ip if it is dropped due to AntiSpoofing?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-the-target-of-source-ip-destiantion-ip-if-it-is/m-p/153668#M25811</link>
      <description>&lt;P&gt;Enabling logging for "Implied Rules" in global properties.&lt;/P&gt;
&lt;P&gt;Which topology option do you currently use, "defined by routes" or other ?&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 10:11:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-the-target-of-source-ip-destiantion-ip-if-it-is/m-p/153668#M25811</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-23T10:11:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to check the target of source ip / destiantion ip if it is dropped due to AntiSpoofing?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-the-target-of-source-ip-destiantion-ip-if-it-is/m-p/153679#M25815</link>
      <description>&lt;P&gt;The logging for antispoofing is located on the Topology screen for each interface here, it is set enabled by default so should be logging anti-spoofing drops unless someone changed it (the state of this checkbox should not be affected by a Get Topology operation):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Spoof.png" style="width: 771px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17284i0A236C67989B945D/image-size/large?v=v2&amp;amp;px=999" role="button" title="Spoof.png" alt="Spoof.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;There is a useful one-liner that can give you a very concise look at your anti-spoofing configuration:&lt;A href="https://community.checkpoint.com/docs/DOC-2990" target="_blank" rel="noopener"&gt;Show Address Spoofing Networks via CLI&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;If you really want to disable anti-spoofing permanently (not recommended) you will need to set these two kernel variables to a value of 0 and make the change permanent in fwkern.conf (first variable) and simkern.conf (second variable):&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fw_antispoofing_enabled&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;sim_anti_spoofing_enabled&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jul 2022 21:18:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-the-target-of-source-ip-destiantion-ip-if-it-is/m-p/153679#M25815</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2022-07-23T21:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to check the target of source ip / destiantion ip if it is dropped due to AntiSpoofing?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-the-target-of-source-ip-destiantion-ip-if-it-is/m-p/153702#M25820</link>
      <description>&lt;P&gt;Here's a question you might be interested in.&lt;/P&gt;&lt;P&gt;A Checkpoint Gateway is used as Second tier Firewall. Every time we get "Network Topology" data from a Gateway object, Anti Spoofing again becomes active.&lt;/P&gt;&lt;P&gt;&lt;A href="https://futbolred.net/" target="_self"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="futbolred.JPG" style="width: 180px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17291iAAC124B2B60D9441/image-size/medium?v=v2&amp;amp;px=400" role="button" title="futbolred.JPG" alt="futbolred.JPG" /&gt;&lt;/span&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jul 2022 18:41:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-the-target-of-source-ip-destiantion-ip-if-it-is/m-p/153702#M25820</guid>
      <dc:creator>cuiko78</dc:creator>
      <dc:date>2022-07-24T18:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to check the target of source ip / destiantion ip if it is dropped due to AntiSpoofing?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-the-target-of-source-ip-destiantion-ip-if-it-is/m-p/153730#M25860</link>
      <description>&lt;P&gt;This is by design. It is the best practice to use antispoofing&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2022 09:29:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-the-target-of-source-ip-destiantion-ip-if-it-is/m-p/153730#M25860</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-25T09:29:37Z</dc:date>
    </item>
  </channel>
</rss>

