On the gateway one of the external interfaces have activated anti-spoofing in detect mode. In tracker i see detections of anti-spoofing but source and destination (gateway external interface) IP-addresses are in the same network (because gateway is satellite in the VPN-community and have a L2 VPN-connection with central office). Why anti-spoofing works in this case? On the attached screenshot external interface with activated anti-spoofing is 10.150.2.6 and network between this gateway and central gateway is 10.150.2.0/28.