Afternoon all.
I've just come off a call with a Check Point TAC support person related to a ticket raised for odd behaviour of anti-spoofing. The TAC person spent a good portion of the call trying to convince me that it is Check Point recommended best practice to have anti-spoofing on internal interfaces set to "detect" instead of "prevent", although when challenged they couldn't point me to any official documentation to that effect.
I've been working with Check Point products since 2006 and this is first time I'm hearing this claim. Anyone else heard this before?