- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
hey
1) how can you enforce AntiSpoofing on interfaces that learn routes from dynamic protocol (OSPF / RIP )?
2) i also have one network which is directlry connected to the FW and in a DR scenario someone will shut the interface and this network will failover to the DR so i need the FW to be updated acordingly with the anti-spoofing configuration
FW Version is R77.30
Antispoofing based on dynamic routing configuration is something that is planned for a later release.
Any updates to the anti-spoofing configuration could be scripted (with the R80.10 API or even with dbedit) but a policy installation is required for it to take effect.
Is there any more update on this topic? I am struggling to find much information.
Thanks
Thank you,
That is an option we can look to test for one of the interfaces. The other interface is defined as external so I don't have that option.
Thank you.
This is something we can try on one of our interfaces that is used for BGP.
The second interface we have is configured as External topology so we don't have the option to select "networks defined by routes".
We will just have to create a group and manually update that when we know of new subnets that are to be advertised to us.
Thanks
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY