<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Anti-spoofing set to &amp;quot;detect&amp;quot; on internal interface recommendation. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Anti-spoofing-set-to-quot-detect-quot-on-internal-interface/m-p/210697#M34887</link>
    <description>&lt;P&gt;Afternoon all.&lt;/P&gt;&lt;P&gt;I've just come off a call with a Check Point TAC support person related to a ticket raised for odd behaviour of anti-spoofing. The TAC person spent a good portion of the call trying to convince me that it is Check Point recommended best practice to have anti-spoofing on internal interfaces set to "detect" instead of "prevent", although when challenged they couldn't point me to any official documentation to that effect.&lt;/P&gt;&lt;P&gt;I've been working with Check Point products since 2006 and this is first time I'm hearing this claim. Anyone else heard this before?&lt;/P&gt;</description>
    <pubDate>Mon, 08 Apr 2024 13:54:53 GMT</pubDate>
    <dc:creator>khodgson_bts</dc:creator>
    <dc:date>2024-04-08T13:54:53Z</dc:date>
    <item>
      <title>Anti-spoofing set to "detect" on internal interface recommendation.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Anti-spoofing-set-to-quot-detect-quot-on-internal-interface/m-p/210697#M34887</link>
      <description>&lt;P&gt;Afternoon all.&lt;/P&gt;&lt;P&gt;I've just come off a call with a Check Point TAC support person related to a ticket raised for odd behaviour of anti-spoofing. The TAC person spent a good portion of the call trying to convince me that it is Check Point recommended best practice to have anti-spoofing on internal interfaces set to "detect" instead of "prevent", although when challenged they couldn't point me to any official documentation to that effect.&lt;/P&gt;&lt;P&gt;I've been working with Check Point products since 2006 and this is first time I'm hearing this claim. Anyone else heard this before?&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 13:54:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Anti-spoofing-set-to-quot-detect-quot-on-internal-interface/m-p/210697#M34887</guid>
      <dc:creator>khodgson_bts</dc:creator>
      <dc:date>2024-04-08T13:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-spoofing set to "detect" on internal interface recommendation.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Anti-spoofing-set-to-quot-detect-quot-on-internal-interface/m-p/210778#M34909</link>
      <description>&lt;P&gt;Prevent is the correct way. Detect is noted in documentation as following (R81)&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_Other.tp_spoof variable"&gt;Anti-Spoofing&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;action is set to&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Select this option to define if packets will be rejected (the Prevent option) or whether the packets will be monitored (the Detect option). The Detect option is used for monitoring purposes and should be used in conjunction with one of the tracking options. It serves as a tool for learning the topology of a network without actually preventing packets from passing.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Preventing-IP-Spoofing.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topics-SECMG/Preventing-IP-Spoofing.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 07:54:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Anti-spoofing-set-to-quot-detect-quot-on-internal-interface/m-p/210778#M34909</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-04-09T07:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: Anti-spoofing set to "detect" on internal interface recommendation.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Anti-spoofing-set-to-quot-detect-quot-on-internal-interface/m-p/210779#M34910</link>
      <description>&lt;P&gt;Prevent is both common &amp;amp; best practice.&lt;/P&gt;
&lt;P&gt;There are exceptions and without further context of the issue / circumstances involved it's difficult to comment further.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Apr 2024 08:07:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Anti-spoofing-set-to-quot-detect-quot-on-internal-interface/m-p/210779#M34910</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-04-09T08:07:11Z</dc:date>
    </item>
  </channel>
</rss>

