Hey guys,
I really hope someone can clarify this for me. Had such strange issue with customer that is running 2 new instances of Azure vmss gateways on R81.20 and 2 still on R81 (until they are removed this or next week).
Anyway, what happened was I realized I could not ssh into either new R81.20 fws and once smart console launched, I saw anti spoofing was enabled, though no changes were done since week ago, when guy from CP PS team told us to leave spoofing off, as it was not supported, which I still find a bit odd, as it does not state that anywhere in the documentation (at least that I can find).
So, what we did was had to reset SIC on both firewalls, as smart dashboard was showing no communication and once that was done and spoofing disabled manually, all was well.
Here are 2 most pressing questions:
1) Is anti spoofing officially supported on Azure vmss CP firewalls?
2) Why would spoofing out of blue be enabled??!! Makes me wonder if there is some sort of script or something on mgmt server that would cause this. Its worth mentioning that on their old R81 vmss gateway, anti spoofing was ENABLED without any problems.
Anyway, I opened a TAC case to see what they have to say, because all this has me baffled, for sure.
Thanks as always for the suggestions/help.
Best regards,
Andy