<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anti-spoofing &amp;quot;Don't check packets from&amp;quot; in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212655#M40388</link>
    <description>&lt;P&gt;'External' means 'everything that isn't configured on one of the internal interfaces'. So make sure your internal interfaces aren't configured to anything too broad, or with a large subnet that overlaps a smaller subnet that routes out the external interface.&lt;/P&gt;
&lt;P&gt;Given the drop happened on the 'eth4' interface, this is the external one?&lt;/P&gt;</description>
    <pubDate>Tue, 30 Apr 2024 01:23:29 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2024-04-30T01:23:29Z</dc:date>
    <item>
      <title>Anti-spoofing "Don't check packets from"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212552#M40363</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I got a problem with Anti-spoofing in my lab. When activating anti-spoofing on an external interface, i cannot install the policy and get this error:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anti1.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25429i5241E1660438D7EF/image-size/large?v=v2&amp;amp;px=999" role="button" title="anti1.JPG" alt="anti1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anti2.JPG" style="width: 795px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25430i9BEA418F1F0389E7/image-size/large?v=v2&amp;amp;px=999" role="button" title="anti2.JPG" alt="anti2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;running "fw unloadlocal" will fix it once, and then it will again send the same error message.&lt;/P&gt;
&lt;P&gt;Disabling anti-spoofing on the external interface and then no problem to install the policy!&lt;/P&gt;
&lt;P&gt;The problem is that adding the 10.1.1.0 subnet under "Don't check packets from" does not help! I still get the same error when trying to install the policy:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anti3.JPG" style="width: 505px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25432iA384AA7A51B713CA/image-size/large?v=v2&amp;amp;px=999" role="button" title="anti3.JPG" alt="anti3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;any ideas!&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 13:40:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212552#M40363</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-04-29T13:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-spoofing "Don't check packets from"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212555#M40364</link>
      <description>&lt;P&gt;Just check first option under topology, not override.&lt;/P&gt;
&lt;P&gt;Also, check this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk115276" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk115276&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can run ip r g 8.8.8.8 to verify routing is good, or run route command from expert mode to confirm.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 13:46:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212555#M40364</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-29T13:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-spoofing "Don't check packets from"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212583#M40369</link>
      <description>&lt;P&gt;Thank you Andy.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;removing&amp;nbsp; "not override"&lt;/STRONG&gt; was the solution for that problem!&lt;/P&gt;
&lt;P&gt;But i still wonder what did that "override" do in that situation?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 14:33:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212583#M40369</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-04-29T14:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-spoofing "Don't check packets from"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212586#M40370</link>
      <description>&lt;P&gt;Or maybe i need to say that it works sometimes:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anti4.JPG" style="width: 802px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25438iC6B9172DFA236852/image-size/large?v=v2&amp;amp;px=999" role="button" title="anti4.JPG" alt="anti4.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;i mean this ping is working sometimes and dropping some other times?!&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 14:43:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212586#M40370</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-04-29T14:43:57Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-spoofing "Don't check packets from"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212587#M40371</link>
      <description>&lt;P&gt;Here is the difference. Though its exact SAME description, you should NEVER change it, specially for external interface, because its auto calculated.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/SmartConsole_OLH/EN/Topics-OLH/ZvkmnUK_XluBBIIAw1mF3A2.htm?cshid=ZvkmnUK_XluBBIIAw1mF3A2" target="_blank"&gt;Interface - Topology Settings (checkpoint.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So, in layman's terms, if you override and set to Internet (external_ though its same as top setting, it may inadvertantly "think" its supposed to calculate the IP from some random external source.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 14:44:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212587#M40371</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-29T14:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-spoofing "Don't check packets from"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212588#M40372</link>
      <description>&lt;P&gt;Mark down below description and use it whenever in doubt, because in my experience, works 100% of the time, just make sure routing is 100% right.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Understanding Topology&lt;/H2&gt;
&lt;P&gt;An interface can be defined as being External (leading to the Internet) or Internal (leading to the LAN).&lt;/P&gt;
&lt;P&gt;The type of network that the interface&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Leads To&lt;/SPAN&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Internet (External)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;This Network (Internal)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- This is the default setting. It is automatically calculated from the topology of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;. To update the topology of an internal network after changes to static routes, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Network Management&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Get Interfaces&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;General Properties&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Override&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Override the default setting.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Override&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;the default setting:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Internet (External)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- All external/Internet addresses&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;This Network (Internal)&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Not Defined&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- All IP addresses behind this interface are considered a part of the internal network that connects to this interface&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Network defined by the interface IP and Net Mask&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Only the network that directly connects to this internal interface&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class="Menu_Options"&gt;Network defined by routes&lt;/SPAN&gt;&amp;nbsp;- The&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&amp;nbsp;dynamically calculates the topology behind this interface. If the network changes, there is no need to click "Get Interfaces" and install a policy.&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Specific&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- A specific network object (a network, a host, an address range, or a network group) behind this internal interface&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;Interface leads to DMZ&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- The DMZ that directly connects to this internal interface&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Mon, 29 Apr 2024 14:46:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212588#M40372</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-29T14:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-spoofing "Don't check packets from"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212591#M40373</link>
      <description>&lt;P&gt;or something like this:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="anti5.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25439iCEC0ED9D1EEB4403/image-size/large?v=v2&amp;amp;px=999" role="button" title="anti5.JPG" alt="anti5.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 14:47:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212591#M40373</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-04-29T14:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-spoofing "Don't check packets from"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212594#M40374</link>
      <description>&lt;P&gt;If you still have issues, I would say it need more investigation. Maybe do fw monitor with -F flag and see whats happening with the traffic. Alternatively, you can do ip r g command to dst IP and make sure route is right.&lt;/P&gt;
&lt;P&gt;Example...if dst is say 10.10.10.10, just run ip r g 10.10.10.10 from expert mode.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;My lab:&lt;/P&gt;
&lt;P&gt;[Expert@cpazurecluster1:0]# ip r g 10.10.10.10&lt;BR /&gt;10.10.10.10 via 10.5.0.1 dev eth0 src 10.5.0.4&lt;BR /&gt;cache&lt;BR /&gt;[Expert@cpazurecluster1:0]#&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 14:53:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212594#M40374</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-04-29T14:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-spoofing "Don't check packets from"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212655#M40388</link>
      <description>&lt;P&gt;'External' means 'everything that isn't configured on one of the internal interfaces'. So make sure your internal interfaces aren't configured to anything too broad, or with a large subnet that overlaps a smaller subnet that routes out the external interface.&lt;/P&gt;
&lt;P&gt;Given the drop happened on the 'eth4' interface, this is the external one?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 01:23:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Anti-spoofing-quot-Don-t-check-packets-from-quot/m-p/212655#M40388</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2024-04-30T01:23:29Z</dc:date>
    </item>
  </channel>
</rss>

