<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anti spoofing and management traffic in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-and-management-traffic/m-p/211565#M40115</link>
    <description>&lt;P&gt;Yeah that would be the best, but have not figured out how I can initiate this traffic for the gateway from the internal interface.&lt;BR /&gt;Please let me know!&lt;BR /&gt;&lt;BR /&gt;Br&lt;/P&gt;</description>
    <pubDate>Wed, 17 Apr 2024 09:40:45 GMT</pubDate>
    <dc:creator>JorgenSpange</dc:creator>
    <dc:date>2024-04-17T09:40:45Z</dc:date>
    <item>
      <title>Anti spoofing and management traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-and-management-traffic/m-p/211553#M40109</link>
      <description>&lt;P&gt;Good day!&lt;BR /&gt;&lt;BR /&gt;We have a checkpoint environment where we need to route traffic to our webproxy on an internal interface.&lt;BR /&gt;&lt;BR /&gt;This causes a problem for the security gateway itself as the traffic towards the proxy is sent from the mgt interface and the return traffic comes back on the internal interface, hence it's getting dropped by anti spoofing.&lt;BR /&gt;If I route the traffic to the webproxy through the mgt interface it works for the gateways, but not for the servers which is also consuming the proxy.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;When defining an interface as internal and using 'defined by routes' adding exceptions to anti spoofing seems to be greyed out.&lt;BR /&gt;&lt;BR /&gt;Does anyone have a good solution on how to solve this?&lt;BR /&gt;&lt;BR /&gt;Br&lt;/P&gt;&lt;P&gt;Jørgen&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 08:11:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-and-management-traffic/m-p/211553#M40109</guid>
      <dc:creator>JorgenSpange</dc:creator>
      <dc:date>2024-04-17T08:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Anti spoofing and management traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-and-management-traffic/m-p/211562#M40113</link>
      <description>&lt;P&gt;Any reason why you don't want to route it all via the internal interface? The best solution is to avoid asymmetrical routing like this, so that anti-spoofing can do its job.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 09:18:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-and-management-traffic/m-p/211562#M40113</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-04-17T09:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Anti spoofing and management traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-and-management-traffic/m-p/211565#M40115</link>
      <description>&lt;P&gt;Yeah that would be the best, but have not figured out how I can initiate this traffic for the gateway from the internal interface.&lt;BR /&gt;Please let me know!&lt;BR /&gt;&lt;BR /&gt;Br&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 09:40:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-and-management-traffic/m-p/211565#M40115</guid>
      <dc:creator>JorgenSpange</dc:creator>
      <dc:date>2024-04-17T09:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Anti spoofing and management traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-and-management-traffic/m-p/211612#M40126</link>
      <description>&lt;P&gt;There's no special configuration required, the gateway just follows the routing table to get to where it needs to. If the route to the destination points out the Internal interface, it will use that.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 13:32:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-and-management-traffic/m-p/211612#M40126</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-04-17T13:32:57Z</dc:date>
    </item>
    <item>
      <title>Re: Anti spoofing and management traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-and-management-traffic/m-p/211613#M40127</link>
      <description>&lt;P&gt;Yeah right, it does. Our problem is that the return traffic will be routed directly to the mgt interface, which will cause it to be dropped by antispoofing. I dont want to route all mgt traffic via the internal interface, as long as we actually are using the dedicated mgmt interface.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2024 13:44:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-and-management-traffic/m-p/211613#M40127</guid>
      <dc:creator>JorgenSpange</dc:creator>
      <dc:date>2024-04-17T13:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: Anti spoofing and management traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-and-management-traffic/m-p/211682#M40145</link>
      <description>&lt;P&gt;In normal deployments, the mgmt interface is just another interface in the box, there's no separation of routing or whatever for management functions. If you want that, you can either redeploy it as VSX or look at Management Data Plane Separation.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk138672" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk138672&lt;/A&gt;&amp;nbsp;&amp;lt; MDPS&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2024 02:03:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-and-management-traffic/m-p/211682#M40145</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-04-18T02:03:17Z</dc:date>
    </item>
  </channel>
</rss>

