- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- How to check the target of source ip / destiantion...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to check the target of source ip / destiantion ip if it is dropped due to AntiSpoofing?
Dear All,
Just find a question here.
We are using the Checkpoint Gateway as Second tier Firewall.
Every time we get "Network Topology" from the Gateway objects, the Anti Spoofing will enable again.
And then the internet traffic is dropped due to the Anti-Spoofing.
but if we check out the traffic log, seems we just got the "allow" message but not "Drop due to Spoofing..."
Please advise.
BTW, how can we disable the Anti-Spoofing forever?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Enabling logging for "Implied Rules" in global properties.
Which topology option do you currently use, "defined by routes" or other ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The logging for antispoofing is located on the Topology screen for each interface here, it is set enabled by default so should be logging anti-spoofing drops unless someone changed it (the state of this checkbox should not be affected by a Get Topology operation):
There is a useful one-liner that can give you a very concise look at your anti-spoofing configuration:Show Address Spoofing Networks via CLI
If you really want to disable anti-spoofing permanently (not recommended) you will need to set these two kernel variables to a value of 0 and make the change permanent in fwkern.conf (first variable) and simkern.conf (second variable):
fw_antispoofing_enabled
sim_anti_spoofing_enabled
March 27th with sessions for both the EMEA and Americas time zones
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is by design. It is the best practice to use antispoofing
