- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi
I got a problem with Anti-spoofing in my lab. When activating anti-spoofing on an external interface, i cannot install the policy and get this error:
running "fw unloadlocal" will fix it once, and then it will again send the same error message.
Disabling anti-spoofing on the external interface and then no problem to install the policy!
The problem is that adding the 10.1.1.0 subnet under "Don't check packets from" does not help! I still get the same error when trying to install the policy:
any ideas!
Just check first option under topology, not override.
Also, check this:
https://support.checkpoint.com/results/sk/sk115276
You can run ip r g 8.8.8.8 to verify routing is good, or run route command from expert mode to confirm.
Best,
Andy
Just check first option under topology, not override.
Also, check this:
https://support.checkpoint.com/results/sk/sk115276
You can run ip r g 8.8.8.8 to verify routing is good, or run route command from expert mode to confirm.
Best,
Andy
Thank you Andy.
removing "not override" was the solution for that problem!
But i still wonder what did that "override" do in that situation?
Or maybe i need to say that it works sometimes:
i mean this ping is working sometimes and dropping some other times?!
Mark down below description and use it whenever in doubt, because in my experience, works 100% of the time, just make sure routing is 100% right.
Andy
An interface can be defined as being External (leading to the Internet) or Internal (leading to the LAN).
The type of network that the interface Leads To:
Internet (External) or This Network (Internal) - This is the default setting. It is automatically calculated from the topology of the gateway. To update the topology of an internal network after changes to static routes, click Network Management > Get Interfaces in the General Properties window of the gateway.
Override - Override the default setting.
If you Override the default setting:
Internet (External) - All external/Internet addresses
This Network (Internal) -
Not Defined - All IP addresses behind this interface are considered a part of the internal network that connects to this interface
Network defined by the interface IP and Net Mask - Only the network that directly connects to this internal interface
Network defined by routes - The gateway dynamically calculates the topology behind this interface. If the network changes, there is no need to click "Get Interfaces" and install a policy.
Specific - A specific network object (a network, a host, an address range, or a network group) behind this internal interface
Interface leads to DMZ - The DMZ that directly connects to this internal interface
or something like this:
If you still have issues, I would say it need more investigation. Maybe do fw monitor with -F flag and see whats happening with the traffic. Alternatively, you can do ip r g command to dst IP and make sure route is right.
Example...if dst is say 10.10.10.10, just run ip r g 10.10.10.10 from expert mode.
Andy
My lab:
[Expert@cpazurecluster1:0]# ip r g 10.10.10.10
10.10.10.10 via 10.5.0.1 dev eth0 src 10.5.0.4
cache
[Expert@cpazurecluster1:0]#
Here is the difference. Though its exact SAME description, you should NEVER change it, specially for external interface, because its auto calculated.
Interface - Topology Settings (checkpoint.com)
So, in layman's terms, if you override and set to Internet (external_ though its same as top setting, it may inadvertantly "think" its supposed to calculate the IP from some random external source.
Best,
Andy
'External' means 'everything that isn't configured on one of the internal interfaces'. So make sure your internal interfaces aren't configured to anything too broad, or with a large subnet that overlaps a smaller subnet that routes out the external interface.
Given the drop happened on the 'eth4' interface, this is the external one?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 16 | |
| 14 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 5 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY