<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checkpoint interface topology in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266268#M52575</link>
    <description>&lt;P&gt;One of the core security features of the product is Anti-Spoofing.&lt;BR /&gt;For anti-spoofing to work, topology must be defined.&lt;BR /&gt;The topology includes all the networks reachable from that interface.&lt;/P&gt;
&lt;P&gt;This can either be done manually or as part of "Get Interfaces with Topology" though you should only use this option before the gateway goes into production.&lt;BR /&gt;This has been discussed here among other places:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246503" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246503&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Dec 2025 23:42:56 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-12-30T23:42:56Z</dc:date>
    <item>
      <title>Checkpoint interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266246#M52573</link>
      <description>&lt;P&gt;Hi team,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I know difference between get interface with topology and without topology meaning. And when we use this, tell me scenario.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2025 16:50:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266246#M52573</guid>
      <dc:creator>Prathmesh131992</dc:creator>
      <dc:date>2025-12-30T16:50:27Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266268#M52575</link>
      <description>&lt;P&gt;One of the core security features of the product is Anti-Spoofing.&lt;BR /&gt;For anti-spoofing to work, topology must be defined.&lt;BR /&gt;The topology includes all the networks reachable from that interface.&lt;/P&gt;
&lt;P&gt;This can either be done manually or as part of "Get Interfaces with Topology" though you should only use this option before the gateway goes into production.&lt;BR /&gt;This has been discussed here among other places:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246503" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/Get-interface/m-p/246503&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Dec 2025 23:42:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266268#M52575</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-12-30T23:42:56Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266275#M52578</link>
      <description>&lt;P&gt;When you get interfaces with topology, Check Point will automatically generate objects for the anti-spoofing settings.&lt;BR /&gt;They will be linked to the interfaces, but may not be visible in the Object Tree. Check:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk126872" target="_blank"&gt;sk126872 - Some Network objects are not visible in the SmartConsole object list&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Something to be aware of if you want to use these objects in a policy.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2025 08:01:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266275#M52578</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2025-12-31T08:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266276#M52579</link>
      <description>&lt;P&gt;Since I encountered problems here and there a long time ago when importing with topology, I have never done it again since then, and the point mentioned that objects are automatically created that I create myself has prevented me from doing it again to this day. But for beginners, I would always recommend importing with topology first and learning how to use as feature correctly.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2025 09:55:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266276#M52579</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2025-12-31T09:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266283#M52582</link>
      <description>&lt;P&gt;I personally never do get interface with topology, as that would reset it all to what fw "thinks" should be defined...its way safer (in my opinion) to do without topology and as long as you set it per routing option, you are good to go, since if something changes on that interface subnet, no need to do anything, it would update it for you.&lt;/P&gt;
&lt;P&gt;Below is what Im referring to and its always good idea to assign the zone as well.&lt;/P&gt;
&lt;P&gt;Also, in simple words, anti spoofing is there so say if interface subnet is on 10.10.10.0/24 and traffic comes from 192.x.x something, it would get dropped.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/SmartConsole_OLH/EN/Topics-OLH/ZvkmnUK_XluBBIIAw1mF3A2.htm?cshid=ZvkmnUK_XluBBIIAw1mF3A2" target="_blank"&gt;Interface - Topology Settings&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32594i3D1BEABFF8EDB3A4/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2025 14:20:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266283#M52582</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-31T14:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266285#M52584</link>
      <description>&lt;P&gt;With dynamic routes, better to either turn it off, not really recommended or as you have said use "Network defined by routes", but ultimately need to keep an eye on it, and would suggest not using prevent mode straight away if you have critical services.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2025 14:36:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266285#M52584</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2025-12-31T14:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint interface topology</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266286#M52585</link>
      <description>&lt;P&gt;100%&lt;/P&gt;</description>
      <pubDate>Wed, 31 Dec 2025 14:37:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-interface-topology/m-p/266286#M52585</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-31T14:37:25Z</dc:date>
    </item>
  </channel>
</rss>

