<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable/enable Anti-spoofing globally on security gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80467#M6203</link>
    <description>&lt;P&gt;For R80.10 and earlier the commands to disable anti-spoofing "on the fly" are:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;fw&amp;nbsp; ctl&amp;nbsp; set&amp;nbsp; int&amp;nbsp; fw_antispoofing_enabled&amp;nbsp; 0&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;sim&amp;nbsp; feature&amp;nbsp; anti_spoofing&amp;nbsp; off; fwaccel&amp;nbsp; off; fwaccel&amp;nbsp; on&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Because you were missing the &lt;STRONG&gt;sim feature&lt;/STRONG&gt; command SecureXL was still enforcing antispoofing.&lt;/P&gt;
&lt;P&gt;For R80.20 Jumbo HFA Take 103+ and R80.30 Jumbo HFA Take 71+, the following is taken from the third edition of my book; this topic is not directly related to performance but I felt it was important enough to cover due to the dire consequences of making a mistake:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-SPOILER&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="trebuchet ms,geneva"&gt;Watch Out: Antispoofing Enforcement&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Antispoofing ensures that traffic is flowing the “correct” way through the firewall,&lt;BR /&gt;based on the packet’s source IP address upon ingress to the firewall, and the packet’s&lt;BR /&gt;destination IP address upon egress of the firewall. Antispoofing is a separate&lt;BR /&gt;enforcement mechanism that is consulted long before any policy layers. Based on the&lt;BR /&gt;recommendations in this chapter, you may need to make firewall topology adjustments to&lt;BR /&gt;ensure traffic is being inspected efficiently by the firewall. Antispoofing relies heavily&lt;BR /&gt;on the firewall’s topology definitions for proper enforcement. If you are not familiar&lt;BR /&gt;with the antispoofing feature or its ramifications, I’d strongly recommend checking out&lt;BR /&gt;the CheckMates post located here: &lt;A href="https://community.checkpoint.com/t5/General-Topics/A-Primer-on-Anti-Spoofing/m-p/23042?search-action-id=13975743881&amp;amp;search-result-uid=23042" target="_self"&gt;A Primer on Anti-Spoofing&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Note that in R80.20 or later firewalls a new dynamic option for calculating&lt;BR /&gt;antispoofing topology for an interface has been introduced, called “Network defined by&lt;BR /&gt;routes”:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="routes.jpg" style="width: 467px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5289i0A27210582537601/image-size/large?v=v2&amp;amp;px=999" role="button" title="routes.jpg" alt="routes.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Figure 8-89: New “Network defined by routes” Setting on R80.20+ Firewalls&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;When selected this option will automatically define the topology for the interface&lt;BR /&gt;based on all directly-connected, static, and dynamic routes referencing that interface. So&lt;BR /&gt;therefore if any antispoofing issues are encountered, the actual problem is probably a&lt;BR /&gt;missing route which can be much easier to troubleshoot.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If you have inherited an existing firewall deployment, or are otherwise unfamiliar&lt;BR /&gt;with its network topology configuration, making sense of the firewall’s defined topology&lt;BR /&gt;from the SmartConsole GUI can be difficult. Nested network groups, a separate screen&lt;BR /&gt;for every interface, and a multitude of anti-spoofing related settings for each individual&lt;BR /&gt;interface can make forming a mental picture of your network and its topology a truly&lt;BR /&gt;daunting task. To make things even more difficult, the firewall’s topology cannot be&lt;BR /&gt;easily viewed from the Management CLI/API interface either.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;However CheckMates user Danny Jung has created a special CLI tool called “One-&lt;BR /&gt;liner for Address Spoofing Troubleshooting” (which won an award for 2019 CheckMates&lt;BR /&gt;Code Hub Contribution of the Year) that provides a no-nonsense, text-based dump of the&lt;BR /&gt;firewall’s topology and associated antispoofing settings from the CLI. Not only is this&lt;BR /&gt;tool useful for troubleshooting antispoofing problems, but is great for figuring out the&lt;BR /&gt;actual working topology of your firewall. The tool is located at CheckMates here: &lt;A href="https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/One-liner-for-Address-Spoofing-Troubleshooting/m-p/33204?search-action-id=13975782420&amp;amp;search-result-uid=33204" target="_self"&gt;One-&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/One-liner-for-Address-Spoofing-Troubleshooting/m-p/33204?search-action-id=13975782420&amp;amp;search-result-uid=33204" target="_self"&gt;liner for Address Spoofing Troubleshooting&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;WARNING&lt;/STRONG&gt;: If you determine that there are missing interfaces in your&lt;BR /&gt;firewall’s topology definition, you might be tempted to click the “Get Interfaces” button&lt;BR /&gt;on the Network Management screen of the firewall object in the SmartConsole. But&lt;BR /&gt;before you do that, look carefully at the Get Interfaces button after clicking it. Note that&lt;BR /&gt;it provides two possible choices when left-clicked (“Get Interfaces With Topology” and&lt;BR /&gt;“Get Interfaces Without Topology”). Clicking the “Get Interfaces Without Topology”&lt;BR /&gt;menu choice is the appropriate one to use in this case to add any missing interfaces.&lt;BR /&gt;Clicking “Get Interfaces With Topology” will attempt to modify the interface topology&lt;BR /&gt;definition of all existing interfaces as well, which may impact anti-spoofing enforcement,&lt;BR /&gt;which could cause a huge outage and even disrupt your ability to manage the firewall!&lt;BR /&gt;Even if you choose the proper “Get Interfaces Without Topology” option, you should&lt;BR /&gt;ALWAYS manually verify the topology of ALL interfaces afterward prior to installing the&lt;BR /&gt;policy!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Should you find yourself cut off from managing or installing policy to the firewall&lt;BR /&gt;due to misconfigured anti-spoofing enforcement, run these expert mode commands on a&lt;BR /&gt;R80.30 Jumbo HFA Take 71+ firewall to disable antispoofing “on the fly”, and recover&lt;BR /&gt;the ability to install a corrected policy (the second line assumes that SecureXL is&lt;BR /&gt;currently enabled on the firewall):&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fw ctl set int fw_antispoofing_enabled 0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;fw ctl set int sim_anti_spoofing_enabled 0 -a&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI-SPOILER&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Apr 2020 13:43:24 GMT</pubDate>
    <dc:creator>Timothy_Hall</dc:creator>
    <dc:date>2020-04-01T13:43:24Z</dc:date>
    <item>
      <title>Disable/enable Anti-spoofing globally on security gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80417#M6193</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Is there a way to disable/enable Anti-spoofing globally on a security gateway rather than doing it specifically on each and every interface? R80.10&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 05:50:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80417#M6193</guid>
      <dc:creator>motiami</dc:creator>
      <dc:date>2020-04-01T05:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/enable Anti-spoofing globally on security gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80419#M6194</link>
      <description>&lt;P&gt;Yes, there is. Just install our &lt;A href="https://community.checkpoint.com/t5/General-Topics/Common-Check-Point-Commands-ccc/td-p/38488" target="_self"&gt;ccc script&lt;/A&gt; and select the specific option within the &lt;EM&gt;Firewall Gateway&lt;/EM&gt; menu.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 06:40:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80419#M6194</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2020-04-01T06:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/enable Anti-spoofing globally on security gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80425#M6195</link>
      <description>&lt;P&gt;Thanks Danny,&lt;/P&gt;&lt;P&gt;Should this script install on each gateway or only on the management server?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 08:33:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80425#M6195</guid>
      <dc:creator>motiami</dc:creator>
      <dc:date>2020-04-01T08:33:01Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/enable Anti-spoofing globally on security gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80429#M6196</link>
      <description>&lt;P&gt;Install it on each gateway. Additionally you can also install it on your management for the management functions it offers. Keep in mind that changing the Anti-spoofing this way might not survive reboots out-of-the-box.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 09:01:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80429#M6196</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2020-04-01T09:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/enable Anti-spoofing globally on security gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80431#M6198</link>
      <description>&lt;P&gt;Thakns,&lt;/P&gt;&lt;P&gt;I have installed it on one of our gateways Clusters , run this command on both Cluster members from the script and installed policy but still, I can see Anti-spoofing logs&lt;/P&gt;&lt;P&gt;fw ctl set int fw_antispoofing_enabled 0 ; fwaccel off; fwaccel on&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I missing something?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 09:01:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80431#M6198</guid>
      <dc:creator>motiami</dc:creator>
      <dc:date>2020-04-01T09:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/enable Anti-spoofing globally on security gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80467#M6203</link>
      <description>&lt;P&gt;For R80.10 and earlier the commands to disable anti-spoofing "on the fly" are:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;fw&amp;nbsp; ctl&amp;nbsp; set&amp;nbsp; int&amp;nbsp; fw_antispoofing_enabled&amp;nbsp; 0&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;sim&amp;nbsp; feature&amp;nbsp; anti_spoofing&amp;nbsp; off; fwaccel&amp;nbsp; off; fwaccel&amp;nbsp; on&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Because you were missing the &lt;STRONG&gt;sim feature&lt;/STRONG&gt; command SecureXL was still enforcing antispoofing.&lt;/P&gt;
&lt;P&gt;For R80.20 Jumbo HFA Take 103+ and R80.30 Jumbo HFA Take 71+, the following is taken from the third edition of my book; this topic is not directly related to performance but I felt it was important enough to cover due to the dire consequences of making a mistake:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-SPOILER&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="trebuchet ms,geneva"&gt;Watch Out: Antispoofing Enforcement&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Antispoofing ensures that traffic is flowing the “correct” way through the firewall,&lt;BR /&gt;based on the packet’s source IP address upon ingress to the firewall, and the packet’s&lt;BR /&gt;destination IP address upon egress of the firewall. Antispoofing is a separate&lt;BR /&gt;enforcement mechanism that is consulted long before any policy layers. Based on the&lt;BR /&gt;recommendations in this chapter, you may need to make firewall topology adjustments to&lt;BR /&gt;ensure traffic is being inspected efficiently by the firewall. Antispoofing relies heavily&lt;BR /&gt;on the firewall’s topology definitions for proper enforcement. If you are not familiar&lt;BR /&gt;with the antispoofing feature or its ramifications, I’d strongly recommend checking out&lt;BR /&gt;the CheckMates post located here: &lt;A href="https://community.checkpoint.com/t5/General-Topics/A-Primer-on-Anti-Spoofing/m-p/23042?search-action-id=13975743881&amp;amp;search-result-uid=23042" target="_self"&gt;A Primer on Anti-Spoofing&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Note that in R80.20 or later firewalls a new dynamic option for calculating&lt;BR /&gt;antispoofing topology for an interface has been introduced, called “Network defined by&lt;BR /&gt;routes”:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="routes.jpg" style="width: 467px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5289i0A27210582537601/image-size/large?v=v2&amp;amp;px=999" role="button" title="routes.jpg" alt="routes.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;Figure 8-89: New “Network defined by routes” Setting on R80.20+ Firewalls&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;When selected this option will automatically define the topology for the interface&lt;BR /&gt;based on all directly-connected, static, and dynamic routes referencing that interface. So&lt;BR /&gt;therefore if any antispoofing issues are encountered, the actual problem is probably a&lt;BR /&gt;missing route which can be much easier to troubleshoot.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;If you have inherited an existing firewall deployment, or are otherwise unfamiliar&lt;BR /&gt;with its network topology configuration, making sense of the firewall’s defined topology&lt;BR /&gt;from the SmartConsole GUI can be difficult. Nested network groups, a separate screen&lt;BR /&gt;for every interface, and a multitude of anti-spoofing related settings for each individual&lt;BR /&gt;interface can make forming a mental picture of your network and its topology a truly&lt;BR /&gt;daunting task. To make things even more difficult, the firewall’s topology cannot be&lt;BR /&gt;easily viewed from the Management CLI/API interface either.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;However CheckMates user Danny Jung has created a special CLI tool called “One-&lt;BR /&gt;liner for Address Spoofing Troubleshooting” (which won an award for 2019 CheckMates&lt;BR /&gt;Code Hub Contribution of the Year) that provides a no-nonsense, text-based dump of the&lt;BR /&gt;firewall’s topology and associated antispoofing settings from the CLI. Not only is this&lt;BR /&gt;tool useful for troubleshooting antispoofing problems, but is great for figuring out the&lt;BR /&gt;actual working topology of your firewall. The tool is located at CheckMates here: &lt;A href="https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/One-liner-for-Address-Spoofing-Troubleshooting/m-p/33204?search-action-id=13975782420&amp;amp;search-result-uid=33204" target="_self"&gt;One-&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/One-liner-for-Address-Spoofing-Troubleshooting/m-p/33204?search-action-id=13975782420&amp;amp;search-result-uid=33204" target="_self"&gt;liner for Address Spoofing Troubleshooting&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;WARNING&lt;/STRONG&gt;: If you determine that there are missing interfaces in your&lt;BR /&gt;firewall’s topology definition, you might be tempted to click the “Get Interfaces” button&lt;BR /&gt;on the Network Management screen of the firewall object in the SmartConsole. But&lt;BR /&gt;before you do that, look carefully at the Get Interfaces button after clicking it. Note that&lt;BR /&gt;it provides two possible choices when left-clicked (“Get Interfaces With Topology” and&lt;BR /&gt;“Get Interfaces Without Topology”). Clicking the “Get Interfaces Without Topology”&lt;BR /&gt;menu choice is the appropriate one to use in this case to add any missing interfaces.&lt;BR /&gt;Clicking “Get Interfaces With Topology” will attempt to modify the interface topology&lt;BR /&gt;definition of all existing interfaces as well, which may impact anti-spoofing enforcement,&lt;BR /&gt;which could cause a huge outage and even disrupt your ability to manage the firewall!&lt;BR /&gt;Even if you choose the proper “Get Interfaces Without Topology” option, you should&lt;BR /&gt;ALWAYS manually verify the topology of ALL interfaces afterward prior to installing the&lt;BR /&gt;policy!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Should you find yourself cut off from managing or installing policy to the firewall&lt;BR /&gt;due to misconfigured anti-spoofing enforcement, run these expert mode commands on a&lt;BR /&gt;R80.30 Jumbo HFA Take 71+ firewall to disable antispoofing “on the fly”, and recover&lt;BR /&gt;the ability to install a corrected policy (the second line assumes that SecureXL is&lt;BR /&gt;currently enabled on the firewall):&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;fw ctl set int fw_antispoofing_enabled 0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;fw ctl set int sim_anti_spoofing_enabled 0 -a&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI-SPOILER&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Apr 2020 13:43:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80467#M6203</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-04-01T13:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: Disable/enable Anti-spoofing globally on security gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80567#M6210</link>
      <description>&lt;P&gt;Thanks, that worked.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Apr 2020 07:35:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Disable-enable-Anti-spoofing-globally-on-security-gateway/m-p/80567#M6210</guid>
      <dc:creator>motiami</dc:creator>
      <dc:date>2020-04-02T07:35:09Z</dc:date>
    </item>
  </channel>
</rss>

