<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic exclude anti-spoofing for communication from specific IP addresses in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-anti-spoofing-for-communication-from-specific-IP/m-p/178315#M32673</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Dear Team,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In the given network environment, is there a way to configure the anti-spoofing settings to exclude communications from specific IP addresses only? The environment is as follows:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Check Point 6200&lt;/LI&gt;&lt;LI&gt;OS: R81.10&lt;/LI&gt;&lt;LI&gt;Anti-spoofing enabled on "external" and "internal" interfaces&lt;/LI&gt;&lt;LI&gt;Topology "external" : External&lt;/LI&gt;&lt;LI&gt;Topology "internal" : 10.10.0.0/16&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The internal topology is set to 10.10.0.0/16,&lt;/P&gt;&lt;P&gt;but communication from 10.10.254.240/28 comes through the external interface.&lt;/P&gt;&lt;P&gt;Is there a good way to exclude this?&lt;/P&gt;</description>
    <pubDate>Tue, 18 Apr 2023 03:14:19 GMT</pubDate>
    <dc:creator>tepeeeeei</dc:creator>
    <dc:date>2023-04-18T03:14:19Z</dc:date>
    <item>
      <title>exclude anti-spoofing for communication from specific IP addresses</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-anti-spoofing-for-communication-from-specific-IP/m-p/178315#M32673</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Dear Team,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In the given network environment, is there a way to configure the anti-spoofing settings to exclude communications from specific IP addresses only? The environment is as follows:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Check Point 6200&lt;/LI&gt;&lt;LI&gt;OS: R81.10&lt;/LI&gt;&lt;LI&gt;Anti-spoofing enabled on "external" and "internal" interfaces&lt;/LI&gt;&lt;LI&gt;Topology "external" : External&lt;/LI&gt;&lt;LI&gt;Topology "internal" : 10.10.0.0/16&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;The internal topology is set to 10.10.0.0/16,&lt;/P&gt;&lt;P&gt;but communication from 10.10.254.240/28 comes through the external interface.&lt;/P&gt;&lt;P&gt;Is there a good way to exclude this?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 03:14:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-anti-spoofing-for-communication-from-specific-IP/m-p/178315#M32673</guid>
      <dc:creator>tepeeeeei</dc:creator>
      <dc:date>2023-04-18T03:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: exclude anti-spoofing for communication from specific IP addresses</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-anti-spoofing-for-communication-from-specific-IP/m-p/178374#M32680</link>
      <description>&lt;P&gt;Yes, select the "Don't check packets from" option on the External interface:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="exclude.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20547i5919FD85FAEC544F/image-size/large?v=v2&amp;amp;px=999" role="button" title="exclude.png" alt="exclude.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 11:46:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-anti-spoofing-for-communication-from-specific-IP/m-p/178374#M32680</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-04-18T11:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: exclude anti-spoofing for communication from specific IP addresses</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-anti-spoofing-for-communication-from-specific-IP/m-p/178418#M32685</link>
      <description>&lt;P&gt;I can't believe it was such a simple solution!&lt;BR /&gt;I feel a bit embarrassed for asking, but thank you for your help.&lt;/P&gt;&lt;P&gt;Just to confirm, with this setting, it will behave as follows, right?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;This setting only disables the spoofing check for packets with the specified IP addresses coming from the external interface.&lt;/LI&gt;&lt;LI&gt;If a packet with the specified IP address as its source comes from the internal side, it won't be considered spoofing either, because the internal topology is set to 10.10.0.0/16.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Thanks again for your assistance, and have a great day!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 23:35:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-anti-spoofing-for-communication-from-specific-IP/m-p/178418#M32685</guid>
      <dc:creator>tepeeeeei</dc:creator>
      <dc:date>2023-04-18T23:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: exclude anti-spoofing for communication from specific IP addresses</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-anti-spoofing-for-communication-from-specific-IP/m-p/178425#M32687</link>
      <description>&lt;P&gt;Not exactly. That setting lets you exempt whatever IP ranges you do NOT want checked for anti spoofing that hit external interface. Be careful though...usually, people may have external peer IPs there, as it may happen there are VPN issues until you place the peer ip address in there. Just my experience, but every case is different. Btw, that setting ONLY works with external or VTI interface, as vti is technically considered "extension" of external interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For packets coming from internal side, its got nothing to do with that setting, as it would hit internal interface, not external.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 02:39:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-anti-spoofing-for-communication-from-specific-IP/m-p/178425#M32687</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-19T02:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: exclude anti-spoofing for communication from specific IP addresses</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-anti-spoofing-for-communication-from-specific-IP/m-p/235053#M45575</link>
      <description>&lt;P&gt;Hey Tim,&lt;/P&gt;&lt;P&gt;Thank You for pointing out solution to this problem as we run into the same predicament last week. Follow up question on this topic:&lt;/P&gt;&lt;P&gt;Do we need to disable button "Calculate topology automatically based on routing information" for Your solution to work? or we can keep it enabled(as we prefer keep it that way)?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Zrzut ekranu 2024-12-09 113615.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28706iECBE4B38CEDE3FFC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Zrzut ekranu 2024-12-09 113615.jpg" alt="Zrzut ekranu 2024-12-09 113615.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 10:36:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-anti-spoofing-for-communication-from-specific-IP/m-p/235053#M45575</guid>
      <dc:creator>konrado_91</dc:creator>
      <dc:date>2024-12-09T10:36:52Z</dc:date>
    </item>
    <item>
      <title>Re: exclude anti-spoofing for communication from specific IP addresses</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-anti-spoofing-for-communication-from-specific-IP/m-p/235099#M45579</link>
      <description>&lt;P&gt;You shouldn't need to disable that option to my knowledge, the override should still work.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2024 19:18:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/exclude-anti-spoofing-for-communication-from-specific-IP/m-p/235099#M45579</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-12-09T19:18:23Z</dc:date>
    </item>
  </channel>
</rss>

