<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPv6 Address Spoofing in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/225402#M43368</link>
    <description>&lt;P&gt;Same here, a hotfix solved the AS problems with IPv6...&lt;/P&gt;</description>
    <pubDate>Tue, 03 Sep 2024 05:34:57 GMT</pubDate>
    <dc:creator>Baumi77</dc:creator>
    <dc:date>2024-09-03T05:34:57Z</dc:date>
    <item>
      <title>IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224611#M43173</link>
      <description>&lt;P&gt;Greetings Everyone,&lt;/P&gt;&lt;P&gt;I have an external interface with IPv6 enabled (::31:2) and a default IPv6 route leading to ::31:1.&lt;/P&gt;&lt;P&gt;Also, Topology calculation is enabled but when I try to ping the interface ::31:2 the firewall drops it as if it is address spoofing.&lt;/P&gt;&lt;P&gt;I haven't found any documentation about this, also I've tried the one liner which doesn't show me much IPv6 information.&lt;/P&gt;&lt;P&gt;Any ideas what can be the issue here?&lt;/P&gt;&lt;P&gt;VSX cluster, coreXL , R81.10 T156&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 08:38:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224611#M43173</guid>
      <dc:creator>ksodan</dc:creator>
      <dc:date>2024-08-27T08:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224626#M43176</link>
      <description>&lt;P&gt;What is the source address from which you are initiating the ping and what is the routing to reach that address?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 11:08:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224626#M43176</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-08-27T11:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224627#M43177</link>
      <description>&lt;P&gt;Source address is from IPv6 GUA range 2001::...&lt;/P&gt;&lt;P&gt;Routing to reach the address is the default route ::/0 through the external interface (PtP between FW and L3 leaf)&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 11:21:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224627#M43177</guid>
      <dc:creator>ksodan</dc:creator>
      <dc:date>2024-08-27T11:21:06Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224678#M43184</link>
      <description>&lt;P&gt;Can you run something like below? Just replace with right ipv6.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;fw ctl zdebug + drop | grep 2001:db8:3333:4444:5555:6666:7777:8888&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 19:23:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224678#M43184</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-27T19:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224680#M43185</link>
      <description>&lt;P&gt;If config is correct and cannot be solved that way you have to open TAC case.&lt;/P&gt;
&lt;P&gt;I have also new issues regarding IPV6 and AS. Custom patch was needed on fwmgmt.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Aug 2024 20:09:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224680#M43185</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-27T20:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224827#M43230</link>
      <description>&lt;P&gt;Hello Andy,&lt;/P&gt;&lt;P&gt;thank you for your time. Here are the results (full ips omitted):&lt;/P&gt;&lt;P&gt;fw6 ctl zdebug + drop&lt;/P&gt;&lt;P&gt;Output:&lt;/P&gt;&lt;P&gt;@;124675495;[kern];[tid_37];[SIM-242006539];pkt_handle_no_match: packet dropped (spoofed address), conn: &amp;lt;&amp;lt;2001:xxxx::dce7,1,fdca::xxxx:32:2,128,58&amp;gt;&amp;gt;, ifn 35&lt;BR /&gt;@;124675495;[kern];[tid_37];[SIM-242006539];sim_pkt_send_drop_notification: (2,0) received drop, reason: Anti-Spoofing, conn: &amp;lt;&amp;lt;2001:xxxx::dce7,1,fdca::xxxx:32:2,128,58&amp;gt;&amp;gt;;&lt;BR /&gt;@;124675495;[kern];[tid_37];[SIM-242006539];sim_pkt_send_drop_notification: sending packet dropped notification drop mode: 0 debug mode: 1 send as is: 0 track_lvl: -1, conn: &amp;lt;2001:xxxx::dce7,1,fdca::xxxx:32:2,128,58&amp;gt;;&lt;BR /&gt;@;124675495;[kern];[tid_37];[SIM-242006539];sim_pkt_send_drop_notification: sending single drop notification, conn: &amp;lt;&amp;lt;2001:xxxx::dce7,1,fdca::xxxx:32:2,128,58&amp;gt;&amp;gt;;&lt;BR /&gt;@;124675495;[kern];[tid_37];[SIM-242006539];do_packet_finish: SIMPKT_IN_DROP vsid=2, conn:&amp;lt;&amp;lt;2001:xxxx::dce7,1,fdca::xxxx:32:2,128,58&amp;gt;&amp;gt;;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 13:08:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224827#M43230</guid>
      <dc:creator>ksodan</dc:creator>
      <dc:date>2024-08-28T13:08:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224833#M43231</link>
      <description>&lt;P&gt;K, so its 100% clear from the drops its anti-spoofing related, as you described in the post. Can you send a screenshot of how those settings are configured from topology please? Just blur out any sensitive data.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 13:21:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224833#M43231</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-28T13:21:02Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224873#M43237</link>
      <description>&lt;P&gt;Certainly, thank you for your time for reviewing this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CPTopology.png" style="width: 560px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27401iEDF767B566AC30A9/image-size/large?v=v2&amp;amp;px=999" role="button" title="CPTopology.png" alt="CPTopology.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;Krešimir&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 17:15:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224873#M43237</guid>
      <dc:creator>ksodan</dc:creator>
      <dc:date>2024-08-28T17:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224875#M43238</link>
      <description>&lt;P&gt;No worries. Can you send how below is configured for that interface?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27402i8FE3CA0848AE921E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 17:30:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224875#M43238</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-28T17:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224882#M43240</link>
      <description>&lt;P&gt;Definitely can !&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot from 2024-08-28 20-06-34.png" style="width: 520px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27403i679B6E0DD61710DC/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot from 2024-08-28 20-06-34.png" alt="Screenshot from 2024-08-28 20-06-34.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 18:08:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224882#M43240</guid>
      <dc:creator>ksodan</dc:creator>
      <dc:date>2024-08-28T18:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224884#M43242</link>
      <description>&lt;P&gt;Thank you! Hey, just wondering, does it let you set it as external zone or not? Because I find it really odd it would be giving those messages, considering there are only so many things you can change with topology on external interface.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 18:28:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224884#M43242</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-28T18:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224885#M43243</link>
      <description>&lt;P&gt;No, thank you for taking your time reviewing my problem. Actually it's automatically set as external when I set the default routes out of the interface.&lt;/P&gt;&lt;P&gt;Works fine with IPv4 that's why I found it unusual in the first place.&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Kresimir&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 18:32:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224885#M43243</guid>
      <dc:creator>ksodan</dc:creator>
      <dc:date>2024-08-28T18:32:30Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224886#M43244</link>
      <description>&lt;P&gt;Do this &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 18:36:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224886#M43244</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-08-28T18:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224887#M43245</link>
      <description>&lt;P&gt;Of course, we are always happy to help mate. By the way, apologies, I see now its VSX, so it makes sense it set it automatic like that. Question...does this ONLY happen when you give the interface ipv6 address, but otherwise no drops for anti-spoofing?&lt;/P&gt;
&lt;P&gt;As a matter of fact, I will assign bogus ipv6 address in my lab to external interface and see what happens when I push the policy.&lt;/P&gt;
&lt;P&gt;Will keep you posted.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 18:36:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224887#M43245</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-28T18:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224893#M43247</link>
      <description>&lt;P&gt;Just tested in the lab, no issues, but then again, I dont have vsx to test, so cant tell really what the main difference is, but in my lab box, I have my external interface set as external zone, like below.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27404i13B6BA1269E794F1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 18:56:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224893#M43247</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-28T18:56:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224959#M43266</link>
      <description>&lt;P&gt;No issues whatsoever with IPv4. Only with IPv6 addresses.&lt;/P&gt;&lt;P&gt;Tried with external security zone but per documentation that should only influence any decisions if security policies are applied to the zone which I don't have at the moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 12:22:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224959#M43266</guid>
      <dc:creator>ksodan</dc:creator>
      <dc:date>2024-08-29T12:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224960#M43267</link>
      <description>&lt;P&gt;Seems like I'll have to resort to this method! Thanks, just wanted to make sure I was not missing something.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 12:23:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224960#M43267</guid>
      <dc:creator>ksodan</dc:creator>
      <dc:date>2024-08-29T12:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224961#M43268</link>
      <description>&lt;P&gt;Yes, thats 100% true, for the external zone. I got nothing else, sorry mate, I would see if TAC may be able to give some suggestions. Though, Im sure there must be some ipv6 gurus here as well : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 12:23:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/224961#M43268</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T12:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: IPv6 Address Spoofing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/225402#M43368</link>
      <description>&lt;P&gt;Same here, a hotfix solved the AS problems with IPv6...&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 05:34:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPv6-Address-Spoofing/m-p/225402#M43368</guid>
      <dc:creator>Baumi77</dc:creator>
      <dc:date>2024-09-03T05:34:57Z</dc:date>
    </item>
  </channel>
</rss>

