- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
I am receiving a lot of detect logs in the firewall caused by the bootp protocol. The problem is that the APs ask for an IP address for the clients using the same interface in which they ask for their own IP address (although they are different networks).
I know I can disable address spoofing for specific networks in the "Gateways and Servers" section but I can´t find anything similar for protocols. I also have thought about using fast_accel but I am not sure if this would work since address spoofing is checked before firewall rules are applied.
So, all in all, Is there any way to bypass the address spoofing check for the bootp protocol?
Thank you!
Firstly, why do you need to do that in the first place?
Also, I don't believe it is possible to bypass antispoofing for some of the traffic but not all the rest.
Finally, please see if you can find your case and resolution in this SK: https://support.checkpoint.com/results/sk/sk104114
bootp is a legacy service so i suspect you configured dhcp incorrectly. Also bypass anti-spoofing with only a service like bootp is not possible. AS is based on IP's / networks. What port is used is not relevant for this feature
@Solkah if both networks, the APs network and the clients network are behind the same interface of your gateway you have to configure both networks for this interface in the AntiSpoofing settings.
Interesting question...personally, never heard of such a thing being feasable, but maybe you can verify with TAC.
Andy
Pretty sure this is not possible, and using fact_accel will not help since SecureXL/sim enforces antispoofing directly on SND's.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY