<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Disable &amp;quot;Local interface address spoofing&amp;quot; in AI Network Firewall</title>
    <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199080#M91237</link>
    <description>&lt;P&gt;yes, of course, this was done first, the network 10.109.118.0/24 is excluded on the External interface. But it didn't help.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wert1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23448iB463F9815F46494D/image-size/large?v=v2&amp;amp;px=999" role="button" title="wert1.png" alt="wert1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Nov 2023 22:40:32 GMT</pubDate>
    <dc:creator>Ilya_Semen</dc:creator>
    <dc:date>2023-11-27T22:40:32Z</dc:date>
    <item>
      <title>Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/14128#M91226</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have a setup, where all the traffic is mirrored to the Checkpoint 5800 (via SPAN port).&lt;/P&gt;&lt;P&gt;Management and mirrored traffic interfaces both have "Anti Spoofing: Disabled",&lt;/P&gt;&lt;P&gt;however, since CP receives mirror of all the traffic (including one from its management interface), logs are filled with&lt;/P&gt;&lt;P&gt;message_info:"Local interface address spoofing" messages&lt;/P&gt;&lt;P&gt;(the MAC address of the mirrored packet is that of the router, not CP device).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can we disable check for "&lt;SPAN&gt;Local interface address spoofing"?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Running&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;R80.20.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 09:28:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/14128#M91226</guid>
      <dc:creator>Tomas_S_</dc:creator>
      <dc:date>2018-11-07T09:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/14129#M91227</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In SmartLog, just enter. &lt;STRONG&gt;not spoofing&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 11:30:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/14129#M91227</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-11-07T11:30:43Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/14130#M91228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wouldn't that only filter output in the view?&lt;/P&gt;&lt;P&gt;We are using&amp;nbsp;cp_log_export, to export logs via syslog, and these are flooded&amp;nbsp;with&amp;nbsp;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;2018-11-07T11:49:58+02:00 local0.info 11.11.11.11 1: 2018-11-07T09:49:54Z ids-n2 CheckPoint 29740 - [action:"Drop"; alert:"alert"; flags:"401408"; ifdir:"inbound"; ifname:"eth1-01"; loguid:"{0x0,0x0,0x0,0x0}"; origin:"11.11.11.11"; originsicname:"cn=cp_mgmt,o=ids-n2.xx.xx.fpp84p"; sequencenum:"530"; time:"1541584194"; version:"5"; __policy_id_tag:"product=VPN-1 &amp;amp; FireWall-1[db_tag={637D2E66-C60F-4646-BD66-FDB8148F5F42};mgmt=ids-n2;date=1541582377;policy_name=Standard\]"; dst:"23.60.24.21"; message_info:"Local interface address spoofing"; product:"VPN-1 &amp;amp; FireWall-1"; proto:"6"; s_port:"38149"; service:"80"; src:"11.11.11.11"; ]&amp;nbsp;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;messages&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 11:57:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/14130#M91228</guid>
      <dc:creator>Tomas_S_</dc:creator>
      <dc:date>2018-11-07T11:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/14131#M91229</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;fw ctl set int fw_local_interface_anti_spoofing 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Second Edition of my "Max Power" Firewall Book&lt;BR /&gt;&lt;SPAN&gt;Now Available at &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.maxpowerfirewalls.com" rel="nofollow"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 12:57:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/14131#M91229</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-11-07T12:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/14132#M91230</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Operation succeded, but messages "&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Local interface address spoofing"&amp;nbsp;&lt;/SPAN&gt;still pour to the fw.log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# fw ctl set int fw_local_interface_anti_spoofing 0&lt;BR /&gt;Set operation succeeded&lt;/P&gt;&lt;P&gt;# fw ctl get int fw_local_interface_anti_spoofing&lt;BR /&gt;fw_local_interface_anti_spoofing = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# sim feature anti_spoofing off; fwaccel off; fwaccel on&lt;/P&gt;&lt;P&gt;Command 'sim feature' has been replaced. Use 'fwaccel feature' instead.&lt;/P&gt;&lt;P&gt;SecureXL device disabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# fwaccel feature anti_spoofing off&lt;BR /&gt;Invalid feature 'anti_spoofing'&lt;BR /&gt;Usage: fwaccel feature &amp;lt;name&amp;gt; {on|off|get}&lt;/P&gt;&lt;P&gt;Available features: sctp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also set:&lt;/P&gt;&lt;P&gt;# fw ctl set int fw_antispoofing_enabled = 0&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 13:34:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/14132#M91230</guid>
      <dc:creator>Tomas_S_</dc:creator>
      <dc:date>2018-11-07T13:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/14133#M91231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After checkpoint reboot the issue is solved: there is no longer spoofing messages in the logs.&lt;/P&gt;&lt;P&gt;Thank You&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Nov 2018 14:08:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/14133#M91231</guid>
      <dc:creator>Tomas_S_</dc:creator>
      <dc:date>2018-11-07T14:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199067#M91232</link>
      <description>&lt;P&gt;Hello Timothy !&lt;/P&gt;&lt;P&gt;Thanks for the answer! I 'm wondering if there will be a negative impact after entering this command on the gateway ?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 20:38:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199067#M91232</guid>
      <dc:creator>Ilya_Semen</dc:creator>
      <dc:date>2023-11-27T20:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199071#M91233</link>
      <description>&lt;P&gt;It won't affect production, it will just keep traffic that the gateway thinks is spoofing its own address from getting dropped.&amp;nbsp; Generally though if you are getting these messages it indicates a network misconfiguration of some kind such as another system in conflict with the firewall's interface IP address, or traffic that was NATted to the firewall's interface address getting incorrectly bounced back to the same firewall&amp;nbsp; interface due to an upstream routing problem.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 21:21:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199071#M91233</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-11-27T21:21:20Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199072#M91234</link>
      <description>&lt;P&gt;Thanks !&lt;BR /&gt;in our scheme, anti-spoofing is in the &amp;nbsp;Net_10.0.0.0(Internal) mode &amp;nbsp;on the Inside interface (anti-spoofing is detect &amp;nbsp;mode) . However, there is a need to connect the office of a partner who uses 10.109.0.0 networks area. &amp;nbsp;With successful initialization IPsec tunnel, we have drop log "&lt;SPAN&gt;Local interface address spoofing". &amp;nbsp;I'm assuming to change the topology for the Inside interface&amp;nbsp;Net_10.0.0.0(Internal) ----&amp;gt; Specific, and&amp;nbsp;to make a set of networks more granular than&amp;nbsp;&amp;nbsp;Net_10.0.0.0(Internal). &amp;nbsp;&amp;nbsp;I hope this helps to win )&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 21:46:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199072#M91234</guid>
      <dc:creator>Ilya_Semen</dc:creator>
      <dc:date>2023-11-27T21:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199075#M91235</link>
      <description>&lt;P&gt;&amp;nbsp;A cleaner way to handle this is adding&amp;nbsp;&lt;SPAN&gt;10.109.0.0 as a "don't check packets from" exception on the External interface here:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dontcheckfrom.png" style="width: 769px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23446i6ED0B26F464A29E6/image-size/large?v=v2&amp;amp;px=999" role="button" title="dontcheckfrom.png" alt="dontcheckfrom.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 22:15:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199075#M91235</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-11-27T22:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199077#M91236</link>
      <description>&lt;P&gt;yes, of course, this was done first, the network 10.109.0.0 is excluded on the External interface. But it didn't help. &amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Снимок экрана 2023-11-28 в 01.30.17.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23447iE032A8066C81A378/image-size/large?v=v2&amp;amp;px=999" role="button" title="Снимок экрана 2023-11-28 в 01.30.17.png" alt="Снимок экрана 2023-11-28 в 01.30.17.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 22:32:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199077#M91236</guid>
      <dc:creator>Ilya_Semen</dc:creator>
      <dc:date>2023-11-27T22:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199080#M91237</link>
      <description>&lt;P&gt;yes, of course, this was done first, the network 10.109.118.0/24 is excluded on the External interface. But it didn't help.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wert1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23448iB463F9815F46494D/image-size/large?v=v2&amp;amp;px=999" role="button" title="wert1.png" alt="wert1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 22:40:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199080#M91237</guid>
      <dc:creator>Ilya_Semen</dc:creator>
      <dc:date>2023-11-27T22:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199082#M91238</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="wewe2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23449i37EF4C01D78820B6/image-size/large?v=v2&amp;amp;px=999" role="button" title="wewe2.png" alt="wewe2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 22:44:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199082#M91238</guid>
      <dc:creator>Ilya_Semen</dc:creator>
      <dc:date>2023-11-27T22:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199083#M91239</link>
      <description>&lt;P&gt;It is the source IP address 10.3.241.1 that is violating anti-spoofing in that log card, not the destination 10.109.118.51.&amp;nbsp; You have one of two situations occurring:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;1) Most likely a routing problem.&amp;nbsp; Traffic was initiated from somewhere bound for 10.109.118.51, it arrived at the firewall who then source NATted it to 10.3.241.1 and sent it out egress interface bond0.801.&amp;nbsp; Some router on the path towards 10.109.118.51 improperly bounced the packet back to the firewall inbound on interface&amp;nbsp;bond0.801 where it was dropped by spoofing.&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;2) IP address 10.3.241.1 is being used by some other host (either on the other side of the VPN or locally) and it conflicts with the firewall's interface IP.&lt;/P&gt;
&lt;P&gt;Either way, turning off local interface spoofing enforcement will not help as the routing for either of these situations is incorrect.&amp;nbsp; If this is VPN traffic, checking "Disable NAT in VPN Community" for the relevant VPN Community might fix the problem, if it is caused by the firewall inappropriately NATting the traffic thus causing situation #1.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 22:52:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199083#M91239</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-11-27T22:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199090#M91240</link>
      <description>&lt;P&gt;Does the fact that 10.109.118.0/24 is behind the SmartLSM gateway matter? and I check VPNcomm settings, &amp;nbsp;yes NAT is disabled for those VPN communities&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="konjjn.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23450i815C390BE0B4E0CD/image-size/large?v=v2&amp;amp;px=999" role="button" title="konjjn.png" alt="konjjn.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 23:01:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199090#M91240</guid>
      <dc:creator>Ilya_Semen</dc:creator>
      <dc:date>2023-11-27T23:01:49Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199096#M91241</link>
      <description>&lt;P&gt;Need a network diagram please.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 23:16:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199096#M91241</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-11-27T23:16:48Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199106#M91242</link>
      <description>&lt;P&gt;In general, the diagram illustrates the current VPN connection. We have a cluster 10.3.24.1 (in HQ) behind it the area 10.0.0.0. SmartLSM SG in the branch,&amp;nbsp;is successfully connected to this cluster, there is a network 10.109.118.0 behind the SmartLSM internal interface. ICMP or another service does not pass from the network 10.3.34.0/24 to the network 10.109.118.0/24. "Local interface address spoofing error" &amp;nbsp;Have one VPN community Star mode, members of this community &amp;nbsp;с26000 and SmartLSM SG.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kjbkbjb.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23455i6453EDDD7FFDDE55/image-size/large?v=v2&amp;amp;px=999" role="button" title="kjbkbjb.png" alt="kjbkbjb.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 01:51:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199106#M91242</guid>
      <dc:creator>Ilya_Semen</dc:creator>
      <dc:date>2023-11-28T01:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199118#M91243</link>
      <description>&lt;P&gt;You almost certainly have a supernetted route for 10.0.0.0 (probably /16 but could be /8) on your HQ firewall pointing to your internal core router.&amp;nbsp; You need a firewall static route for&amp;nbsp;&lt;SPAN&gt;10.109.118.0/24 with the next hop your Internet perimeter router.&amp;nbsp; Because you don't have this, the traffic to&amp;nbsp;10.109.118.0 is being NATed by the firewall then hairpinned right back to your internal core router, who promptly&amp;nbsp;bounces it right back to the firewall which then drops it for spoofing.&amp;nbsp; Like I said, a routing issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;You also need to ensure that the 10.109.118.0 network is not part of the VPN domain definition for the HQ firewall, a "group with exclusion" object is typically used for this purpose.&amp;nbsp; Obviously&amp;nbsp;10.109.118.0 must appear in the VPN domain for the remote firewall.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2023 02:37:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199118#M91243</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2023-11-28T02:37:40Z</dc:date>
    </item>
    <item>
      <title>Re: Disable "Local interface address spoofing"</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199545#M91244</link>
      <description>&lt;P&gt;You are absolutely right! Our routing was implemented poorly. Our network engineers fixed the situation and the problem with Local Spoofing &amp;nbsp;was solved. Thanks again for the help!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 02 Dec 2023 17:44:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Disable-quot-Local-interface-address-spoofing-quot/m-p/199545#M91244</guid>
      <dc:creator>Ilya_Semen</dc:creator>
      <dc:date>2023-12-02T17:44:07Z</dc:date>
    </item>
  </channel>
</rss>

