Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JaySon_2021
Contributor
Jump to solution

Disable Anti Spoofing on EXTERNAL interface necessary?

Is it necessary to disable anti-spoofing for the External interface when you specify it as EXTERNAL? 

When I look at the AntiSpoofing cfg for an interface in the firewall object I see 'Perform AntiSpoofing based on interface topology'. If I say the interface is Internet (External), wouldn't that suggest that ANY address could hit that interface AND there is no need to disable anti-spoofing?

If not, why when I specify the interface is 'Internet (External)' would the SMS not automatically disable AntiSpoofing?

Thanks

0 Kudos
2 Solutions

Accepted Solutions
the_rock
MVP Diamond
MVP Diamond

Do NOT do that, please. If any issues, I would simply set it to detect, but only for testing. Otherwise, you can always add IPs as an exemption, so those are not checked for anti spoofing. Whole point of it in simple words to ensure that whatever subnet is supposed to hit any given interface, actually does that. Otherwise, packets will be spoofed and you certainly dont want that. Just leave it as external (leading to Internet).

Reference:

https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topi...

https://sc1.checkpoint.com/documents/R80.30/SmartConsole_OLH/EN/html_frameset.htm?topic=documents/R8...

Best,
Andy

View solution in original post

0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

It's not 'Any', it's 'Anything that isn't specified in an internal interface's anti-spoofing configuration'. So it's not pointless and you should leave it on. 

View solution in original post

2 Replies
the_rock
MVP Diamond
MVP Diamond

Do NOT do that, please. If any issues, I would simply set it to detect, but only for testing. Otherwise, you can always add IPs as an exemption, so those are not checked for anti spoofing. Whole point of it in simple words to ensure that whatever subnet is supposed to hit any given interface, actually does that. Otherwise, packets will be spoofed and you certainly dont want that. Just leave it as external (leading to Internet).

Reference:

https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SecurityManagement_AdminGuide/Topi...

https://sc1.checkpoint.com/documents/R80.30/SmartConsole_OLH/EN/html_frameset.htm?topic=documents/R8...

Best,
Andy
0 Kudos
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

It's not 'Any', it's 'Anything that isn't specified in an internal interface's anti-spoofing configuration'. So it's not pointless and you should leave it on. 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events