- CheckMates
- :
- Products
- :
- General Topics
- :
- Antispoofing in external interfaces when Cluster I...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Antispoofing in external interfaces when Cluster IP Addresses on Different Subnets
Hello,
I'm working in a scenario where we have 3 interfaces with 3 public ips that now are going to be turned into a cluster. For that, I am following the workaround "Cluster IP Addresses on Different Subnets" to save public ips on those interfaces. The workaround is clear and works on lab.
The issue is that when using that workaround, it is mandatory to specify the antispoofing object or installation fails:
The Anti-spoofing setting for this configuration should be specific and not "This net". Usually, you should choose the Cluster IP or the Member's IP subnet or define a group with these two subnets and use it.
- Policy verification failed.
For internal interfaces, this is simple, you just add a specific network group/object with the internal interfaces as usual to override the antispoofing and thats it, but, what if like in my case these are external interfaces? What is the best practice for this? Just put the "All internet" object in the antispoofing settings of those 3 interfaces?
Thanks!!
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No - Change the Anti-Spoofing configuration of your Internet interface to "Internet (External)"
See https://support.checkpoint.com/results/sk/sk180814
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No - Change the Anti-Spoofing configuration of your Internet interface to "Internet (External)"
See https://support.checkpoint.com/results/sk/sk180814
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Albrecht
I tried to delete the post as I tested your solution a couple of minutes ago and it worked. Just defining the interfaces as "Internet (External). One of them is not defined as external, so we will change it and it will work.
Thanks
