- CheckMates
- :
- Products
- :
- General Topics
- :
- A simple question on Anti-spoofing ?
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A simple question on Anti-spoofing ?
Hi Checkmates,
First, please have a look at the snap of my topology.
1> When I try to take SSH of the interface eth2 from PC1, why am I not denied the access by anti-spoofing, because I come with a different IP (10.10.10.10) to eth2 interface.
2> Will my request get internally routed within the Check Point GW and get accepted ?
Can somebody help me with my simple question.
Thanks in advance !
======
WR,
FH
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You come from eth1 with subnet 10.10.10.0/24 with an IP in that range, so anti-spoofing won't block you there.
The access control policy could allow or block you.
Anti-spoofing, depending how it's configured, will check the validity of the source IP incoming on any given interface, to put it simply.
Eth2 would perform anti-spoofing if you came in with 10.10.10.10 as source on that interface if you choose to match interface IP and range for instance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the reply @Alex- ,
So how many times is the traffic inspected at the firewall, won't it check the SRC IP is 10.10.10.10 and the DST is 20.20.20.0/24 and block it.
Can you put this step by step please ?
====
WR,
FH
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
See here:
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey brother,
@Alex- is 100% right. Btw, check below, I find its basic, but an EXCELLENT reference.
Andy
