<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic Routing Anti Spoofing in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/55372#M4178</link>
    <description>I would agree with Maarten -- You really shouldn't have to define a custom group if you are defining it as an external interface.</description>
    <pubDate>Sun, 09 Jun 2019 14:04:12 GMT</pubDate>
    <dc:creator>Bryce_Myers</dc:creator>
    <dc:date>2019-06-09T14:04:12Z</dc:date>
    <item>
      <title>Dynamic Routing Anti Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/19342#M1470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hey&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) how can you enforce AntiSpoofing on interfaces that learn routes from dynamic protocol&amp;nbsp; (OSPF / RIP )?&lt;/P&gt;&lt;P&gt;2) i also have one network which is directlry connected to the FW and in a DR scenario someone will shut the interface and this network will failover to the DR so i need the FW to be updated acordingly with the anti-spoofing configuration&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FW Version is R77.30&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Dec 2017 11:18:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/19342#M1470</guid>
      <dc:creator>Dor_Marcovitch</dc:creator>
      <dc:date>2017-12-19T11:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Routing Anti Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/19343#M1471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Antispoofing based on dynamic routing configuration is something that is planned for a later release.&lt;/P&gt;&lt;P&gt;Any updates to the anti-spoofing configuration could be scripted (with the R80.10 API or even with dbedit) but a policy installation is required for it to take effect.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Dec 2017 00:17:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/19343#M1471</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-12-20T00:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Routing Anti Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/55268#M4170</link>
      <description>&lt;P&gt;Is there any more update on this topic? I am struggling to find much information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2019 08:42:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/55268#M4170</guid>
      <dc:creator>scottikon</dc:creator>
      <dc:date>2019-06-07T08:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Routing Anti Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/55309#M4173</link>
      <description>If you are running 80.20 gateway and management you should be able to select "Network Defined by Routes". I haven't tested this in my environment dynamic routing.</description>
      <pubDate>Fri, 07 Jun 2019 21:17:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/55309#M4173</guid>
      <dc:creator>Bryce_Myers</dc:creator>
      <dc:date>2019-06-07T21:17:36Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Routing Anti Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/55326#M4174</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is an option we can look to test for one of the interfaces. The other interface is defined as external so I don't have that option.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jun 2019 11:29:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/55326#M4174</guid>
      <dc:creator>scottikon</dc:creator>
      <dc:date>2019-06-08T11:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Routing Anti Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/55327#M4175</link>
      <description>&lt;P&gt;Thank you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is something we can try on one of our interfaces that is used for BGP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The second interface we have is configured as External topology so we don't have the option to select "networks defined by routes".&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will just have to create a group and manually update that when we know of new subnets that are to be advertised to us.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jun 2019 12:19:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/55327#M4175</guid>
      <dc:creator>scottikon</dc:creator>
      <dc:date>2019-06-08T12:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Routing Anti Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/55334#M4176</link>
      <description>I think you should ask yourself the question here, why are you using External on that interface if you still need to Anti-Spoofing?&lt;BR /&gt;In fact an interface set to external with enabled Anti-Spoofing will just use a scheme that says: anything is allowed that is not defined by all other (non External) interfaces.</description>
      <pubDate>Sat, 08 Jun 2019 18:10:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/55334#M4176</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-06-08T18:10:25Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Routing Anti Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/55372#M4178</link>
      <description>I would agree with Maarten -- You really shouldn't have to define a custom group if you are defining it as an external interface.</description>
      <pubDate>Sun, 09 Jun 2019 14:04:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Dynamic-Routing-Anti-Spoofing/m-p/55372#M4178</guid>
      <dc:creator>Bryce_Myers</dc:creator>
      <dc:date>2019-06-09T14:04:12Z</dc:date>
    </item>
  </channel>
</rss>

