<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISP blocks traffic - Their anti-spoofing system - Same VMAC for 3 interfaces in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/ISP-blocks-traffic-Their-anti-spoofing-system-Same-VMAC-for-3/m-p/18597#M3347</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. We finally disabled vmac option. And solved our problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 13 Dec 2018 16:33:56 GMT</pubDate>
    <dc:creator>Diego_Javier_Me</dc:creator>
    <dc:date>2018-12-13T16:33:56Z</dc:date>
    <item>
      <title>ISP blocks traffic - Their anti-spoofing system - Same VMAC for 3 interfaces</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-blocks-traffic-Their-anti-spoofing-system-Same-VMAC-for-3/m-p/18595#M3345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;TABLE cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR style="height: 180px;"&gt;&lt;TD class="" style="border-left: 1px solid #f3f3f3; font-size: 11.2px; padding: 10px 0px 0px 6px; height: 180px;"&gt;&lt;DIV class=""&gt;&lt;DIV lang="EN-GB"&gt;&lt;DIV class=""&gt;&lt;P class="" style="font-size: 11pt; margin: 0cm 0cm 0.0001pt;"&gt;There is a Check Point cluster. Two 5200 series appliances.&lt;/P&gt;&lt;P class="" style="font-size: 11pt; margin: 0cm 0cm 0.0001pt;"&gt;Three Internet services connected to the cluster, from the same ISP. They see three IP addresses (each cluster's Internet address for each link) with the same MAC address (checkpoint cluster's virtual mac). That causes their system to activate an antispoofing alert and it periodically blocks the traffic.&lt;/P&gt;&lt;P class="" style="font-size: 11pt; margin: 0cm 0cm 0.0001pt;"&gt;Is there any way to set and independant VMACs?&lt;/P&gt;&lt;P class="" style="font-size: 11pt; margin: 0cm 0cm 0.0001pt;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="" style="font-size: 11pt; margin: 0cm 0cm 0.0001pt;"&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P class="" style="font-size: 11pt; margin: 0cm 0cm 0.0001pt;"&gt;&lt;/P&gt;&lt;P class="" style="font-size: 11pt; margin: 0cm 0cm 0.0001pt;"&gt;&lt;SPAN lang="ES-AR"&gt;Best Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2018 19:04:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-blocks-traffic-Their-anti-spoofing-system-Same-VMAC-for-3/m-p/18595#M3345</guid>
      <dc:creator>Diego_Javier_Me</dc:creator>
      <dc:date>2018-11-21T19:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISP blocks traffic - Their anti-spoofing system - Same VMAC for 3 interfaces</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-blocks-traffic-Their-anti-spoofing-system-Same-VMAC-for-3/m-p/18596#M3346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know many people don't want to hear this but with VRRP you can choose for Extended VMAC, which is a deviate of the IP address and will be different for each interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Nov 2018 21:32:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-blocks-traffic-Their-anti-spoofing-system-Same-VMAC-for-3/m-p/18596#M3346</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-11-21T21:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISP blocks traffic - Their anti-spoofing system - Same VMAC for 3 interfaces</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-blocks-traffic-Their-anti-spoofing-system-Same-VMAC-for-3/m-p/18597#M3347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. We finally disabled vmac option. And solved our problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Dec 2018 16:33:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-blocks-traffic-Their-anti-spoofing-system-Same-VMAC-for-3/m-p/18597#M3347</guid>
      <dc:creator>Diego_Javier_Me</dc:creator>
      <dc:date>2018-12-13T16:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISP blocks traffic - Their anti-spoofing system - Same VMAC for 3 interfaces</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-blocks-traffic-Their-anti-spoofing-system-Same-VMAC-for-3/m-p/18598#M3348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When employing ClusterXL HA, the "use VMAC" option is unchecked by default and my opinion is that it should be left that way if possible.&amp;nbsp; Failovers will utilize the Gratuitous ARP mechanism when the VMAC box is unchecked, and that will usually work just fine in most networks.&amp;nbsp; However if "slow" or incomplete failovers for all NAT addresses are encountered, VMAC can be enabled but it may honk of the switching infrastructure (and STP) in various ways as described above.&amp;nbsp; At a minimum, make sure portfast is configured on the firewall's switchports if you plan to enable VMAC...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Dec 2018 13:25:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-blocks-traffic-Their-anti-spoofing-system-Same-VMAC-for-3/m-p/18598#M3348</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-12-14T13:25:13Z</dc:date>
    </item>
  </channel>
</rss>

