<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ping between SYNC being dropped by Anti-spoofing in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Ping-between-SYNC-being-dropped-by-Anti-spoofing/m-p/81236#M16414</link>
    <description>What's the routing table look like on the affected gateway?&lt;BR /&gt;Because you should be able to use the same (private) sync network on each cluster, AFAIK.</description>
    <pubDate>Wed, 08 Apr 2020 00:57:15 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-04-08T00:57:15Z</dc:date>
    <item>
      <title>Ping between SYNC being dropped by Anti-spoofing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ping-between-SYNC-being-dropped-by-Anti-spoofing/m-p/81203#M16405</link>
      <description>&lt;P&gt;I have an R80.20 cluster. The SYNC interfaces are configured as follows:&lt;/P&gt;&lt;P&gt;FW1 - 192.168.199.1/255.255.255.252&lt;/P&gt;&lt;P&gt;FW2 - 192.168.199.2/255.255.255.252&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Antispoofing (from the default) is as follows:&lt;/P&gt;&lt;P&gt;Leads To - This Network (Internal)&lt;/P&gt;&lt;P&gt;Security Zone - User defined (I have never defined any security zones)&lt;/P&gt;&lt;P&gt;Anti-spoofing - Perform anti-spoofing based on interface topology&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the firewall logs, after I ping from .1 to .2 I see the ICMP being permitted, immediately followed by a DROP and a statement 'Cluster member IP is being spoofed'.&lt;/P&gt;&lt;P&gt;What am I missing in my antispoofing config? Its at the default.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 20:45:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ping-between-SYNC-being-dropped-by-Anti-spoofing/m-p/81203#M16405</guid>
      <dc:creator>J_Saun</dc:creator>
      <dc:date>2020-04-07T20:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Ping between SYNC being dropped by Anti-spoofing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ping-between-SYNC-being-dropped-by-Anti-spoofing/m-p/81204#M16406</link>
      <description>&lt;P&gt;Update&lt;/P&gt;&lt;P&gt;I scrutinized the logs again and the logger shows the source as being the SYNC interface of a DIFFERENT firewall cluster in our environment. The SYNC connections are direct, not through a switch. How is that possible?&lt;/P&gt;&lt;P&gt;Does that mean we cannot use the same, small, 192.168.199.0/30 network on all of our SYNC interfaces? They have to be different?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 20:50:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ping-between-SYNC-being-dropped-by-Anti-spoofing/m-p/81204#M16406</guid>
      <dc:creator>J_Saun</dc:creator>
      <dc:date>2020-04-07T20:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Ping between SYNC being dropped by Anti-spoofing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Ping-between-SYNC-being-dropped-by-Anti-spoofing/m-p/81236#M16414</link>
      <description>What's the routing table look like on the affected gateway?&lt;BR /&gt;Because you should be able to use the same (private) sync network on each cluster, AFAIK.</description>
      <pubDate>Wed, 08 Apr 2020 00:57:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Ping-between-SYNC-being-dropped-by-Anti-spoofing/m-p/81236#M16414</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-08T00:57:15Z</dc:date>
    </item>
  </channel>
</rss>

