<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Address spoofing in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Address-spoofing/m-p/182188#M30371</link>
    <description>&lt;P&gt;I think below is the key.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115276&amp;amp;srcFavorites=favorites" target="_blank"&gt;https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115276&amp;amp;srcFavorites=favorites&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21094i20F6F4BFB2A3BDCC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would do some packet captures to make sure flow of traffic is indeer correct.&lt;/P&gt;</description>
    <pubDate>Thu, 25 May 2023 19:40:20 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-05-25T19:40:20Z</dc:date>
    <item>
      <title>Address spoofing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Address-spoofing/m-p/182183#M30369</link>
      <description>&lt;P&gt;I have network with 2 gateways, one is CP other is Mikrotik.&lt;/P&gt;&lt;P&gt;Mikrotik is in its own vlan. No access to any part of CP network.&lt;/P&gt;&lt;P&gt;Network have about 50 vlans, intervlan routing is done by L3 switch. (no routing for mikrotiks vlan)&lt;/P&gt;&lt;P&gt;CP is GW for all networks accept for vlan of mikrotik.&lt;/P&gt;&lt;P&gt;Everything is working fine. I can not access mikrotik vlan form any&amp;nbsp; CP network and vice versa.&lt;/P&gt;&lt;P&gt;few days ago I found logs on CP:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Interface Direction: inbound&lt;BR /&gt;Interface Name: eth0&lt;BR /&gt;Id Generated By Indexer:false&lt;BR /&gt;First: true&lt;BR /&gt;Sequencenum: 4&lt;BR /&gt;Source: 10.20.0.89 (this is network, that is used for "Mikrotik network"&lt;BR /&gt;Source Port: 4500&lt;BR /&gt;Destination: x.x.x.x&lt;BR /&gt;Destination Port: 4500&lt;BR /&gt;IP Protocol: 17&lt;BR /&gt;Message Information: Address spoofing&lt;BR /&gt;Action: Detect&lt;BR /&gt;Type: Log&lt;BR /&gt;Blade: Firewall&lt;BR /&gt;Service: UDP/4500&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Interface: eth0&lt;BR /&gt;Description: IKE_NAT_TRAVERSAL Traffic Detected from 10.20.0.89 to x.x.x.x&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with x.x.x.x I hided public IP address of destination, but it is legit IP WAN address.&lt;/P&gt;&lt;P&gt;privat IP is allways the same (10.20.0.89) that is strange, because there was few same events in range of few days (DHCP leash time on Mikrotik is 1day and I do not use reservations)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Obviously I have some misconfiguration on network or someone is doing something bad on network.&lt;/P&gt;&lt;P&gt;I did try my best to&amp;nbsp;repeat the event, but I cant find way to do it.&lt;/P&gt;&lt;P&gt;I couldn't&amp;nbsp; find it on Mikrotik DHCP log, since leash time released IP.&lt;/P&gt;&lt;P&gt;How can I find out what is going on? Few users have access to both networks, is it possible that Windows (or software) somehow route two networks together? Mikrotik is WiFi network.&lt;/P&gt;&lt;P&gt;I want to replicate this event, so I will know what is wrong and protect network.&lt;/P&gt;&lt;P&gt;Is this misconfiguration of the LAN, misconfiguration of endpoint PC or is someone really spoofing LAN address?&lt;/P&gt;&lt;P&gt;No other traffic is detected on CP from "Mikrotik network" only this IP and only&amp;nbsp;IKE_NAT_TRAVERSAL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 19:16:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Address-spoofing/m-p/182183#M30369</guid>
      <dc:creator>WhOPP</dc:creator>
      <dc:date>2023-05-25T19:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: Address spoofing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Address-spoofing/m-p/182188#M30371</link>
      <description>&lt;P&gt;I think below is the key.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115276&amp;amp;srcFavorites=favorites" target="_blank"&gt;https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115276&amp;amp;srcFavorites=favorites&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21094i20F6F4BFB2A3BDCC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would do some packet captures to make sure flow of traffic is indeer correct.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 19:40:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Address-spoofing/m-p/182188#M30371</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-25T19:40:20Z</dc:date>
    </item>
  </channel>
</rss>

