<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to prevent IP spoofing from internet? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122227#M22652</link>
    <description>&lt;P&gt;There's a couple things:&lt;/P&gt;
&lt;P&gt;1. You define the topology on the gateway as to what's considered valid on the gateway for a given interface. In R80.20+ you can also let this be dynamically defined by the routing table.&lt;BR /&gt;2. We block the use of IP Options, which allows you to encode a route back to the IP.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jun 2021 20:38:41 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-06-25T20:38:41Z</dc:date>
    <item>
      <title>How to prevent IP spoofing from internet?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122219#M22649</link>
      <description>&lt;P&gt;Can someone help me to understand how checkpoint firewall prevents IP spoofing from the internet?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 19:04:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122219#M22649</guid>
      <dc:creator>Binoy</dc:creator>
      <dc:date>2021-06-25T19:04:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent IP spoofing from internet?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122227#M22652</link>
      <description>&lt;P&gt;There's a couple things:&lt;/P&gt;
&lt;P&gt;1. You define the topology on the gateway as to what's considered valid on the gateway for a given interface. In R80.20+ you can also let this be dynamically defined by the routing table.&lt;BR /&gt;2. We block the use of IP Options, which allows you to encode a route back to the IP.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 20:38:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122227#M22652</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-25T20:38:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent IP spoofing from internet?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122241#M22653</link>
      <description>&lt;P&gt;you can also search " Anti-Spoofing" in the Security Gateway Administration Guide for your corresponding version to read up on more detail&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jun 2021 01:48:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122241#M22653</guid>
      <dc:creator>Cyber_Serge</dc:creator>
      <dc:date>2021-06-26T01:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent IP spoofing from internet?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122251#M22655</link>
      <description>&lt;P&gt;I would refer to below link, it explains it very well:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.20/SmartConsole_OLH/EN/html_frameset.htm?topic=documents/R80.20/SmartConsole_OLH/EN/ZvkmnUK_XluBBIIAw1mF3A2" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.20/SmartConsole_OLH/EN/html_frameset.htm?topic=documents/R80.20/SmartConsole_OLH/EN/ZvkmnUK_XluBBIIAw1mF3A2&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;gave you correct answer. Put it this way...there is an option on external interface to exempt any IP address, but you definitely do not want to turn off anti spoofing on external interface, thats a huge security issue. In some scenario, I seen people set it to "detect" on internal interface, but thats not as bad, since that would be used for outbound traffic anyway.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jun 2021 11:49:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122251#M22655</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-26T11:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent IP spoofing from internet?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122443#M22681</link>
      <description>&lt;P&gt;If you activate IP spoofing on your interfaces, It will help to IP spoofing attacks.&amp;nbsp; If attacker send a packet with the spoofed address into your servers It can prevent.&amp;nbsp;For example, your Eth1 is configured 192.168.1.0/24 subnetting, then It will drop the packet if firewall receive this subnet IP come from another interface...&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 06:59:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122443#M22681</guid>
      <dc:creator>Baasanjargal_Ts</dc:creator>
      <dc:date>2021-06-29T06:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent IP spoofing from internet?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122452#M22683</link>
      <description>&lt;P&gt;Thank you very much for the reply.&lt;/P&gt;&lt;P&gt;1. I understand that we can enable Anti-spoofing on interfaces based on the topology. Whether I need to enable anti-spoofing on Internet facing interface? As the default route is pointing to internet, how will it detect IP spoofing?&lt;/P&gt;&lt;P&gt;2. Whether IPS blade is required to block the IP Options. Could you please help to understand how to do it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 08:09:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122452#M22683</guid>
      <dc:creator>Binoy</dc:creator>
      <dc:date>2021-06-29T08:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to prevent IP spoofing from internet?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122537#M22689</link>
      <description>&lt;P&gt;For external interfaces, anything not defined on an internal interface would be considered invalid on the external interface.&lt;/P&gt;
&lt;P&gt;IP Options checking is actually done in the firewall (not IPS) and done by default.&lt;BR /&gt;Modifying this behavior requires editing some .def files on the management and pushing policy.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jun 2021 20:38:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-to-prevent-IP-spoofing-from-internet/m-p/122537#M22689</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-29T20:38:20Z</dc:date>
    </item>
  </channel>
</rss>

