I'm working on a system at the moment that has a single cluster and has been linked to SASE with redundant tunnels. This is all working fine, however when you push the policy it completes with a warning about no anti-spoofing in the VTI interfaces. Having not worked with route based VPN's before, I just wanted to check to see if there are any reasons not to simply enable the anti-spoofing as usual on these interfaces?
They show as "Leads To: Point to point" and it appears that you can enable it in prevent mode only as there is no option to select between Detect and Prevent.