Hello guys,
Is there any way how to monitor anti-spoofing traffic in R77.30 ? I know that I can choose Alert, Log or None in spoofing properties for specific interface. But does someone know how to send for example syslog event in case gateway recognize spoofing traffic ? Or send mail ...
Searching all logs to found "spoofing" word in Information isnt good approach... There must be something on CLI how to check if interface faced spoofing traffic (as it issue log event towards log server).
Thanks for every suggestion in advance.
One place you can see anti-spoofing drop packets (albeit not on a specific interface) is cpview.
If you want Alerts to run a script, you can set that in Global Properties (but will apply for anything with Log type set to Alert):