- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
We have some centrally managed SMB Appliances running as clusters (ClusterXL HA Mode New). We want to let the appliance do the correct AntiSpoofing by itself automatically. We use static routing (but also have some devices running dynamic routing). In the Gateway Cluster Properties we have the option "Automatically calculated by teh gateway, based on the Gateways's Routing Table".
When adding a new interface, we begin with configuring the interfaces in Gaia WebUI. Then we modify the Gateway Cluster Properties with SmartConsole. Under Topology we "Edit Topology". Then we click on "Get" with option "All Member's Interfaces with Topology...". Afterwards we manually add the ip, mask and name of the cluster interface and set the type to "Cluster". Then we install the policy. This made the cluster IP appear on the devices (cphaprob -a if). Unfortunately packets are getting dropped by the firewall with reason "AntiSpoofing".
What do we miss? Do we have to invoke "Copy topology to cluster interfaces"? We are struggling because we do not want to break the other existing and working interfaces. We are looking for documentation and advice on how to do it properly.
Versions:
1590 Appliance R80.20.35 - Build 467
SmartManagement R81.10 - Build 029
SmartConsole R81.10.9600.412
Thanks a lot in advance!
sk115276: How to troubleshoot "Local interface address spoofing" issues
This sk seems unrelated to my question on "How to properly add a new interface with AntiSpoofing calculated automatically". Have I missed something?
All you need to know is this...IF calculated automatically, it will reset anything configured manually, which may not be intended option you want. Most customers I know just manually edit them (though this is regular Gaia, not embedded), so you can confirm subnets behind that interface are indeeed 100% right. Though in SMB cluster case, as long as routing is correct, I dont see loigically why you cant leave it as automatic.
Andy
What can I do here?
In this window you can define all the interfaces on this host or gateway.
Note: This topic refers to these Small Office Appliances: CPSG 80 series, 1100 and 1200R appliances.
What background information do I need to know?
Topology is a physical or logical structure of computer-related objects. Topology defines how the network node connects to the networks inside and outside the organization. The node is connected to networks via interfaces. A gateway has two types of interfaces:
Interfaces are defined by an IP address and a netmask address. The interfaces on the gateway can be defined manually or automatically by pressing Get....
In the Gateway - Topology page, the topology is set automatically because it represents the hard coded device.
The set topology includes the following three interfaces (two internal and one external):
Although these three interfaces automatically appear in the Topology window, they are not associated with an IP address and a Network Mask.
If you deselect the Dynamic Address option in the General Properties window and add a static IP address, the WAN automatically receives the specified static IP address and its Network Mask is 255.255.255.255.
The Type drop-down list in the General Properties window defines the hardware type and its associated topology. Currently all hardware types share the same topology. Every hardware type has one external interface and two internal interfaces. It is possible to add only one additional external interface.
Do I need to press the button "Copy topology to cluster interfaces"?
If its cluster, it would make sense, yes
Do I have to press "Copy topology to cluster interfaces" after "Get - All Member's Interfaces with Topology..."?
Based on the explanation, I would say yes, but you can verify with TAC.
I need to know how to set "the Topology" for a virtual cluster interface. At the moment I guess the button "Copy topology to cluster interfaces" is the only way to do it, in case "Automatically calculated by the gateway, based on the Gateways's Routing Table" is active. But I'm going to open a TAC case...
Good idea, just to be 100% sure.
I'm still waiting for advice from TAC. Is there really no documentation on this topic?
I think the best "documentation" you would find on this is help section from smart dashboard, thats it.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY