I have a couple of situation where traffic is being dropped due to anti-spoofing. From what i read i should update the FW's sense of the network's topology by doing a "Get interfaces with topology". When i try and do this it takes about 20 minutes then presents me with over 500 changes. At that point i wimp out and press "cancel".
Is this because every route would have an entry? - I've got loads of OSPF routes and BGP un-aggregrated prefixes in my routing table.
If i try and install 500 changes is this ok? I worry that if it goes wrong or i am doing this wrong then 500 changes is a hell of a lot to walk back from.