I have an R80.20 cluster. The SYNC interfaces are configured as follows:
FW1 - 192.168.199.1/255.255.255.252
FW2 - 192.168.199.2/255.255.255.252
Antispoofing (from the default) is as follows:
Leads To - This Network (Internal)
Security Zone - User defined (I have never defined any security zones)
Anti-spoofing - Perform anti-spoofing based on interface topology
In the firewall logs, after I ping from .1 to .2 I see the ICMP being permitted, immediately followed by a DROP and a statement 'Cluster member IP is being spoofed'.
What am I missing in my antispoofing config? Its at the default.