Glad to hear that it works, but having anti-spoofing disabled long-term is not where you want to be. Having to do that to get things working would indicate that traffic is not routing the way you think it is, and disabling anti-spoofing is now possibly allowing ICMP redirects to "correct" the situation for you. Relying on this redirect mechanism to keep things running is notoriously unstable so watch out, here are the pages covering this from my last book (no I am not a skilled graphic artist, this is why I work in IT):
Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com