I was checking sk32500 - Anti-spoofing on VSX (static and dynamic) in order to manage anti-spoofing on a VSX which has switched from static to dynamic routing and enforce anti-spoofing.
Steps so far:
- Dynamic routing enabled and working
- Disable "Calculate topology automatically based on routing information" at the VS level
- Edit the relevant interface and select "Internal - Defined by routes" for the topology
- Set the anti-spoofing to Detect for initial verification
But then, sources coming from the interface which match prefixes received by the dynamic routing protocol on that interface are flagged as anti-spoofing with the yellow shield as we are in detection mode.
So if a prefix on interface bond10.20 is learnt as 10.1.1.0/24, we see for instance 10.1.1.1 flagged as spoofed with direction incoming on that interface in the logs.
We are probably missing something, but what? Any tips are welcome.
CP appliances, R81.10 Take 150.