<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Network Defined by Routes: Anti-Spoofing in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154662#M26249</link>
    <description>&lt;P&gt;Network defined by routes should include dynamic routes as well. By default the system is pulling all kernel routes every second.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Here is where you can check the settings:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-08-06 at 21.33.01.png" style="width: 886px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17396i72EDE38768811FFA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-08-06 at 21.33.01.png" alt="Screenshot 2022-08-06 at 21.33.01.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 06 Aug 2022 19:33:51 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2022-08-06T19:33:51Z</dc:date>
    <item>
      <title>Network Defined by Routes: Anti-Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154653#M26245</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;I'd like to seek your help in configuring the Anti-spoofing config. We'll be configuring the firewalls (R81.10) in Active/Standby as follows:-&lt;/P&gt;&lt;P&gt;Internet Firewall eth1 (10.0.0.1/30) -&amp;gt; (10.0.0.2/30) Internet Router (Public IP) -&amp;gt; ISP -&amp;gt; Internet&lt;/P&gt;&lt;P&gt;Internet Firewall eth2 (10.2.0.1/30) -&amp;gt; (10.2.0.2/30) Internal Firewall -&amp;gt; Core switch -&amp;gt; Internal Networks&lt;/P&gt;&lt;P&gt;On eth1, as this is a private IP, should I need to just configure the "External (Internet)" or I need to select External (Internet) WITH the Anti-spoofing exceptions of the egress private IP (10.0.0.0/30)&lt;/P&gt;&lt;P&gt;Also, on eth2, should I need to select the "&lt;SPAN&gt;network defined by routes" or I need to manually specify the Internal networks in a network-group? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Note: We've static route (10.0.0.0/8, 172.16.0.0/16) from the Internet-facing firewalls to the Internal firewalls which is further connecting to the Core switches.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your support !&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Aug 2022 09:30:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154653#M26245</guid>
      <dc:creator>SriNarasimha005</dc:creator>
      <dc:date>2022-08-06T09:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Network Defined by Routes: Anti-Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154657#M26246</link>
      <description>&lt;P&gt;The simplest explanation is that if a given source address is expected to communicate from behind a particular interface it needs to be accounted for in its anti-spoofing configuration.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Network defined by routes option can be helpful in reducing the ongoing manual maintenance of the spoofing configuration (note it doesn't work precisely the same a URPF).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Aug 2022 11:37:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154657#M26246</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-06T11:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: Network Defined by Routes: Anti-Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154659#M26247</link>
      <description>&lt;P&gt;Hi Mate,&lt;/P&gt;&lt;P&gt;Thanks for the reply. But my query is that, should be private IP address of the eth1 be included as an exception or just configuring 'External' interface works like a charm?&lt;/P&gt;&lt;P&gt;Also, since I'm using static route for traffic forwarding towards Internal networks, do I need to add the networks to be accounted for in the network group manually?&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm of opinion that, 'Network defined by routes' would work for the dynamic routing and would like to get your assistance on the above.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks in advance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Aug 2022 15:30:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154659#M26247</guid>
      <dc:creator>SriNarasimha005</dc:creator>
      <dc:date>2022-08-06T15:30:24Z</dc:date>
    </item>
    <item>
      <title>Re: Network Defined by Routes: Anti-Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154662#M26249</link>
      <description>&lt;P&gt;Network defined by routes should include dynamic routes as well. By default the system is pulling all kernel routes every second.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Here is where you can check the settings:&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-08-06 at 21.33.01.png" style="width: 886px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17396i72EDE38768811FFA/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-08-06 at 21.33.01.png" alt="Screenshot 2022-08-06 at 21.33.01.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Aug 2022 19:33:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154662#M26249</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-08-06T19:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Network Defined by Routes: Anti-Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154663#M26250</link>
      <description>&lt;P&gt;&lt;SPAN&gt;I would create an exception for the private network in case there is overlap.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Static &amp;amp; dynamic, note we don't take the priority/rank into consideration here.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Aug 2022 00:16:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154663#M26250</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-07T00:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Network Defined by Routes: Anti-Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154664#M26251</link>
      <description>&lt;P&gt;Hi Mate,&lt;/P&gt;&lt;P&gt;Thanks for your help so far. From the reply, I'd assume, that 'network defined by routes' would consider static route as well to calculate topology behind an interface (and not just dynamic routing).&lt;/P&gt;&lt;P&gt;And, final one, we've a remote-access VPN solution (non-checkpoint product) where users are provisioned with the IP address of 10.19.5.0/24. Should I need to create an exception for the same on "External" interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Aug 2022 04:09:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154664#M26251</guid>
      <dc:creator>SriNarasimha005</dc:creator>
      <dc:date>2022-08-07T04:09:47Z</dc:date>
    </item>
    <item>
      <title>Re: Network Defined by Routes: Anti-Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154666#M26252</link>
      <description>&lt;P&gt;If the clients on this private range are accessing things behind the Check Point routing in via it's external interface then most likely yes.&lt;/P&gt;</description>
      <pubDate>Sun, 07 Aug 2022 06:07:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Network-Defined-by-Routes-Anti-Spoofing/m-p/154666#M26252</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-07T06:07:39Z</dc:date>
    </item>
  </channel>
</rss>

