I have come across an environment where the SMS security gateway cluster object and it's members are using the security gateways clusterxl physical interface IP's. The SMS IP is NOT in the same subnet as the security gateways. I believe normally this would have reachability issues to the standby firewall as traffic from the SMS going to the gateway would hit the VIP first and outbound traffic from the standby would use the VIP as a source. The client has disabled "enable extended cluster anti-spoof" through Network Topology so it appears to fix the reachability issues. For whatever reason they did not utilize the Mgmt interafces and have used the clustered transit VLAN interafces for the cluster object. What is recommended in this situation, move to Mgmt interface or other "private" Interface, leave it with the cluster anti-spoof turned off?