<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISP advance DMZ getting rejected on 1570 in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238277#M11948</link>
    <description>&lt;P&gt;Good morning Experts,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I enable this feature, the WAN port on the 1590 receives the external IP of the modem but my internet stops working because the firewall sees it as an address spoofing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Normal DMZ would assign me an internal address and that works fine. I want to move away from using the PPPoE client on the firewall all together.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway I can disable this without disabling it globally ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 11 Jan 2025 15:03:33 GMT</pubDate>
    <dc:creator>MrDazanaCom</dc:creator>
    <dc:date>2025-01-11T15:03:33Z</dc:date>
    <item>
      <title>ISP advance DMZ getting rejected on 1570</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238277#M11948</link>
      <description>&lt;P&gt;Good morning Experts,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I enable this feature, the WAN port on the 1590 receives the external IP of the modem but my internet stops working because the firewall sees it as an address spoofing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Normal DMZ would assign me an internal address and that works fine. I want to move away from using the PPPoE client on the firewall all together.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyway I can disable this without disabling it globally ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jan 2025 15:03:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238277#M11948</guid>
      <dc:creator>MrDazanaCom</dc:creator>
      <dc:date>2025-01-11T15:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISP advance DMZ getting rejected on 1590</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238279#M11949</link>
      <description>&lt;P&gt;I cant sadly confirm this, as I dont have smb to test, but, if its centrally managed, you can do this via network settings on the object, like you would on regular fw. If its locally managed, I remember seeing before command from clish -&amp;gt; set antispoofing&lt;/P&gt;
&lt;P&gt;You can tab once you type that and see what options it gives you.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jan 2025 13:58:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238279#M11949</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-11T13:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISP advance DMZ getting rejected on 1590</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238281#M11950</link>
      <description>&lt;P&gt;Are you able to share some more details of the IP addresses used and the drop traffic log perhaps?&lt;/P&gt;
&lt;P&gt;Also which version of software is used with the 1590?&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jan 2025 14:09:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238281#M11950</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-01-11T14:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISP advance DMZ getting rejected on 1590</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238284#M11951</link>
      <description>&lt;P&gt;Sure thing. My bad, its a 1570 not a 1590&lt;/P&gt;&lt;P&gt;running&amp;nbsp;&lt;SPAN&gt;R81.10.10 (996002993)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dmz_advance1.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29158iCAAC1B0E9B14E284/image-size/large?v=v2&amp;amp;px=999" role="button" title="dmz_advance1.jpg" alt="dmz_advance1.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="advance_dmz2_error.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29159i961FB458B4DB8821/image-size/large?v=v2&amp;amp;px=999" role="button" title="advance_dmz2_error.jpg" alt="advance_dmz2_error.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After the Advance DMZ is activated, the interface gets the modems ip address&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dhcp2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29162i3F2340FA56FF961D/image-size/large?v=v2&amp;amp;px=999" role="button" title="dhcp2.jpg" alt="dhcp2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Jan 2025 15:00:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238284#M11951</guid>
      <dc:creator>MrDazanaCom</dc:creator>
      <dc:date>2025-01-11T15:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISP advance DMZ getting rejected on 1590</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238305#M11954</link>
      <description>&lt;P&gt;When I run the command&amp;nbsp;&lt;SPAN class=""&gt;set&lt;/SPAN&gt; interface WAN antispoofing off i get&amp;nbsp;Bad parameter starting at 'antispoofing off'&lt;/P&gt;&lt;P&gt;show configuration only shows the following for antispoofing&amp;nbsp;&lt;/P&gt;&lt;P&gt;# Anti-spoofing&lt;BR /&gt;set antispoofing advanced-settings global-activation "true"&lt;/P&gt;&lt;P&gt;set vpn remote-access advanced-settings office-mode single-om-per-site "false" om-perform-antispoofing "false"&lt;/P&gt;&lt;P&gt;I don't see an interface where its enabled just enabled global&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jan 2025 15:13:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238305#M11954</guid>
      <dc:creator>MrDazanaCom</dc:creator>
      <dc:date>2025-01-12T15:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISP advance DMZ getting rejected on 1590</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238307#M11955</link>
      <description>&lt;P&gt;I totally see what you are saying, thats unfortunate : - (. I just created tech point spark lab and seems that is indeed the case. Maybe someone else can confirm for sure if its possible...did you ever end up opening TAC case?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29164i2FADD0C553F27D27/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jan 2025 15:39:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238307#M11955</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-12T15:39:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISP advance DMZ getting rejected on 1590</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238308#M11956</link>
      <description>&lt;P&gt;No I never did open a TAC case&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jan 2025 16:35:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238308#M11956</guid>
      <dc:creator>MrDazanaCom</dc:creator>
      <dc:date>2025-01-12T16:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISP advance DMZ getting rejected on 1590</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238309#M11957</link>
      <description>&lt;P&gt;I more asked just to see if you got their feedback, but I really dont believe its possible. Even in web UI, I went through all the settings for WAN interface, there is absolutely nothing for antispoofing.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jan 2025 16:38:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238309#M11957</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-12T16:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISP advance DMZ getting rejected on 1590</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238311#M11958</link>
      <description>&lt;P&gt;I disabled the Anti spoofing globally, I get an external wan address from the isp modem and&amp;nbsp; it still doesn't work. No errors in the logs this time around only stuff like can't resolve host names. Very odd. Thanks for your input&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jan 2025 17:36:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238311#M11958</guid>
      <dc:creator>MrDazanaCom</dc:creator>
      <dc:date>2025-01-12T17:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISP advance DMZ getting rejected on 1590</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238314#M11959</link>
      <description>&lt;P&gt;So when you say it stil does not work, I assume you mean Internet access does not work? If so, what are the errors now in the logs?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jan 2025 19:31:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/ISP-advance-DMZ-getting-rejected-on-1570/m-p/238314#M11959</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-12T19:31:04Z</dc:date>
    </item>
  </channel>
</rss>

