Hi @Roy_Smith
I think it's R80.30. I could see these problems with several other gateways. Here the TAC is also involved.
1) Are your office mode addresses of IP spoofing used for internal interfaces? This may also cause this error.
2) Is IP spoofing active for the office mode pool?
3) Or set don't check packets from:
Emergency solution:
From my point of view, change to detect mode of IP spoofing on the external interface is not very security relevant.
Why! All internet IP addresses are allowed here. Private addresses 10.x.x.x, 192.168.x.x, ... are not routed in the internet. If you now drop IP addresses from 224.0.0.0-255.255.255.254, you are reasonably safe. But keep in mind that you have to activate certain multicast IPs (for example HSRP, VRRP,...). But you should also allow 255.255.255.255 in individual cases.
I think the solution is not nice, but you can live with it.
Then you can analyze the issues. The goal should be to enable IP spoofing again.
➜ CCSM Elite, CCME, CCTE ➜ www.checkpoint.tips