<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Strange Anti-spoof messages on Cluster IP Address in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-Anti-spoof-messages-on-Cluster-IP-Address/m-p/103433#M8156</link>
    <description>&lt;P&gt;I have a weird issue where if I ping a server e.g 10.9.8.7/27 it does not respond, but If I ping 10.9.8.6/27 it does work. This is via a static route to say 10.5.5.5/29 which is directly connected to interface bond1.123 on the Firewall. Cluster Address 10.5.5.1/29.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Upon checking logs it shows Cluster member IP address spoofing only from 10.9.8.7, not 10.9.8.6. The network 10.9.8.0/27 is specifically&amp;nbsp; in the group to allow traffic in the anti-spoof group for Interface bond1.123.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone ever seen this before? when I do a cpstop it works! , All very strange.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Thu, 26 Nov 2020 13:49:39 GMT</pubDate>
    <dc:creator>Alan_Camelo1</dc:creator>
    <dc:date>2020-11-26T13:49:39Z</dc:date>
    <item>
      <title>Strange Anti-spoof messages on Cluster IP Address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-Anti-spoof-messages-on-Cluster-IP-Address/m-p/103433#M8156</link>
      <description>&lt;P&gt;I have a weird issue where if I ping a server e.g 10.9.8.7/27 it does not respond, but If I ping 10.9.8.6/27 it does work. This is via a static route to say 10.5.5.5/29 which is directly connected to interface bond1.123 on the Firewall. Cluster Address 10.5.5.1/29.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Upon checking logs it shows Cluster member IP address spoofing only from 10.9.8.7, not 10.9.8.6. The network 10.9.8.0/27 is specifically&amp;nbsp; in the group to allow traffic in the anti-spoof group for Interface bond1.123.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone ever seen this before? when I do a cpstop it works! , All very strange.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 13:49:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-Anti-spoof-messages-on-Cluster-IP-Address/m-p/103433#M8156</guid>
      <dc:creator>Alan_Camelo1</dc:creator>
      <dc:date>2020-11-26T13:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Strange Anti-spoof messages on Cluster IP Address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-Anti-spoof-messages-on-Cluster-IP-Address/m-p/103441#M8157</link>
      <description>&lt;P&gt;We have a tool in our ToolBox that might be of help: &lt;A href="https://community.checkpoint.com/t5/SmartConsole-Extensions/Interface-Topology-for-gateways/m-p/81871" target="_self"&gt;SmartConsole Extension to show the calculated interface topology of a gateway&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 14:10:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-Anti-spoof-messages-on-Cluster-IP-Address/m-p/103441#M8157</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2020-11-26T14:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Strange Anti-spoof messages on Cluster IP Address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-Anti-spoof-messages-on-Cluster-IP-Address/m-p/103448#M8159</link>
      <description>&lt;P&gt;Thanks Danny, but I don't think that would help as the spoofing groups all look correct in the topology.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll give it a try and let you know.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 14:20:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-Anti-spoof-messages-on-Cluster-IP-Address/m-p/103448#M8159</guid>
      <dc:creator>Alan_Camelo1</dc:creator>
      <dc:date>2020-11-26T14:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Strange Anti-spoof messages on Cluster IP Address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-Anti-spoof-messages-on-Cluster-IP-Address/m-p/103461#M8160</link>
      <description>&lt;P&gt;Can you provide screenshots of your interface topology within SmartConsole please?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 15:32:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-Anti-spoof-messages-on-Cluster-IP-Address/m-p/103461#M8160</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2020-11-26T15:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Strange Anti-spoof messages on Cluster IP Address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-Anti-spoof-messages-on-Cluster-IP-Address/m-p/103516#M8166</link>
      <description>&lt;P&gt;Hi Jack, I cant really provide screenshots but here is the best I can Show, the issue is trying to ping 10.9.8.7 (10.9.8.6 is OK)&lt;/P&gt;&lt;P&gt;Interface bond1.1203 - 10.5.5.1/29&lt;/P&gt;&lt;P&gt;Route to&amp;nbsp;&lt;SPAN&gt;10.9.8.0/27 via 10.5.5.5 (next hop router)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Networks in spoof group for Interface bond1.1203&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;10.5.5.0/29 and&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;10.9.8.0/27&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Logs show Cluster spoof from 10.9.8.7 to 10.5.5.1.&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2020 10:08:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-Anti-spoof-messages-on-Cluster-IP-Address/m-p/103516#M8166</guid>
      <dc:creator>Alan_Camelo1</dc:creator>
      <dc:date>2020-11-27T10:08:00Z</dc:date>
    </item>
  </channel>
</rss>

