- CheckMates
- :
- Products
- :
- Developers
- :
- API / CLI Discussion
- :
- How to check if Anti-Spoofing is enabled and set t...
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to check if Anti-Spoofing is enabled and set to Prevent mode for each interface on CLI?
Which CLI command will let me know if each interface has Anti-Spoofing enabled and set to Prevent mode?
This command is not specific enough:
fw ctl get int fw_antispoofing_enabled
3 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't believe there is a way to pull this information directly out of the running kernel, but the cached policy INSPECT files on the gateway can be queried for this info using this tool:
Attend my 60-minute "Be your Own TAC: Part Deux" Presentation
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm
Exclusively at CPX 2025 Las Vegas Tuesday Feb 25th @ 1:00pm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That kernel variable just tells you that it's been disabled in the kernel. You need to query the actual installed policy to see if it's really enabled or not.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks. This command will easily show if there is at least one interface not running in Prevent mode:
grep ":monitor_only (true)" $FWDIR/state/local/FW1/local.set
and this command shows if there is at least one interface that has Anti-Spoofing disabled:
grep ":has_addr_info (false)" $FWDIR/state/local/FW1/local.set
I also added these checks to our ccc script.
data:image/s3,"s3://crabby-images/c1c8f/c1c8f352ba4f5587e322202d12667fbf3857d2f1" alt=""