Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
BlueGrass
Contributor

How to check the target of source ip / destiantion ip if it is dropped due to AntiSpoofing?

Dear All,

 

Just find a question here.

 

We are using the Checkpoint Gateway as Second tier Firewall.

 

Every time we get "Network Topology" from the Gateway objects, the Anti Spoofing will enable again.

 

And then the internet traffic is dropped due to the Anti-Spoofing.

 

but if we check out the traffic log, seems we just got the "allow" message but not "Drop due to Spoofing..."

 

Please advise.

 

BTW, how can we disable the Anti-Spoofing forever?

0 Kudos
4 Replies
Chris_Atkinson
Employee
Employee

Enabling logging for "Implied Rules" in global properties.

Which topology option do you currently use, "defined by routes" or other ?

CCSM R77/R80/ELITE
0 Kudos
Timothy_Hall
Champion
Champion

The logging for antispoofing is located on the Topology screen for each interface here, it is set enabled by default so should be logging anti-spoofing drops unless someone changed it (the state of this checkbox should not be affected by a Get Topology operation):

Spoof.png

There is a useful one-liner that can give you a very concise look at your anti-spoofing configuration:Show Address Spoofing Networks via CLI  

If you really want to disable anti-spoofing permanently (not recommended) you will need to set these two kernel variables to a value of 0 and make the change permanent in fwkern.conf (first variable) and simkern.conf (second variable):

fw_antispoofing_enabled

sim_anti_spoofing_enabled

Updated 2023 IPS/AV/ABOT R81.20 Course now
available at maxpowerfirewalls.com
0 Kudos
cuiko78
Explorer

Here's a question you might be interested in.

A Checkpoint Gateway is used as Second tier Firewall. Every time we get "Network Topology" data from a Gateway object, Anti Spoofing again becomes active.

futbolred.JPG

0 Kudos
_Val_
Admin
Admin

This is by design. It is the best practice to use antispoofing

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events