Create a Post

Antispoofing Detect Bypassing ACL Policy



I have a Checkpoint Cluster in AWS whose external interface topology is defined as 

eth0: defined by routes 

Antispoofing - Detect

This is due to the fact that some Private IPs are also hitting eth0 for communication hence Antispoofing is set to Dectect.

There is a requirement where i need to allow access to internal web server from a sepcific group of Public IPs only.. the problem is even after restricting it from ACL .. traffic is getting allowed from all over the Internet and the logs for that access is under Action - "Detect" .. some how its not hitting ACL .. is this the expected behaviour ? why is the traffic not hitting ACL when the Anti spoofing is set to Detect..



0 Kudos
3 Replies
This widget could not be displayed.