- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Dear Team,
In the given network environment, is there a way to configure the anti-spoofing settings to exclude communications from specific IP addresses only? The environment is as follows:
The internal topology is set to 10.10.0.0/16,
but communication from 10.10.254.240/28 comes through the external interface.
Is there a good way to exclude this?
Yes, select the "Don't check packets from" option on the External interface:
Yes, select the "Don't check packets from" option on the External interface:
I can't believe it was such a simple solution!
I feel a bit embarrassed for asking, but thank you for your help.
Just to confirm, with this setting, it will behave as follows, right?
Thanks again for your assistance, and have a great day!
Not exactly. That setting lets you exempt whatever IP ranges you do NOT want checked for anti spoofing that hit external interface. Be careful though...usually, people may have external peer IPs there, as it may happen there are VPN issues until you place the peer ip address in there. Just my experience, but every case is different. Btw, that setting ONLY works with external or VTI interface, as vti is technically considered "extension" of external interface.
For packets coming from internal side, its got nothing to do with that setting, as it would hit internal interface, not external.
Hey Tim,
Thank You for pointing out solution to this problem as we run into the same predicament last week. Follow up question on this topic:
Do we need to disable button "Calculate topology automatically based on routing information" for Your solution to work? or we can keep it enabled(as we prefer keep it that way)?
You shouldn't need to disable that option to my knowledge, the override should still work.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY