CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-12-03
clarkeyi clarkeyi is offline
Member
 
Join Date: 2005-12-18
Posts: 41
Rep Power: 0
clarkeyi has an average reputation (10+)
Default IP Spoofing on our internal LAN

I have a queastion regarding multiple subnets on our LAN. We have the original 100.x network on our LAN and now we have added a 10.x network. When I create a rule for 10.x traffic to pass through our firewall it drops the rule with IP spoofing error messages. I can understand this but is there any way to allow the 2 subnets to be allowed through our internal interface which is configured to only allow 100.x in the topology settings?

Thanks
Reply With Quote
  #2 (permalink)  
Old 2007-12-03
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 434
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: IP Spoofing on our internal LAN

1) create a group
2) Insert your local networks into this group (objects for 100.x net and 10.x)
3) Edit your gateways topology/antispoofing settings on your internal interface and set this group you created as object
4) install policy
Reply With Quote
  #3 (permalink)  
Old 2007-12-03
clarkeyi clarkeyi is offline
Member
 
Join Date: 2005-12-18
Posts: 41
Rep Power: 0
clarkeyi has an average reputation (10+)
Default Re: IP Spoofing on our internal LAN

Thanks for the advice
Reply With Quote
  #4 (permalink)  
Old 2007-12-12
fdamstra fdamstra is offline
Junior Member
 
Join Date: 2006-05-20
Posts: 28
Rep Power: 0
fdamstra has an average reputation (10+)
Default Re: IP Spoofing on our internal LAN

Quote:
Originally Posted by clarkeyi View Post
I have a queastion regarding multiple subnets on our LAN. We have the original 100.x network on our LAN and now we have added a 10.x network. When I create a rule for 10.x traffic to pass through our firewall it drops the rule with IP spoofing error messages. I can understand this but is there any way to allow the 2 subnets to be allowed through our internal interface which is configured to only allow 100.x in the topology settings?
It would be far better to separate your traffic into separate vlan's and use subinterfaces on your firewall. This requires that you have a decent managed switch, but would decrease the size of the broadcast domain.

Having two subnets on a single VLAN is not best practice. It's not scalable, offers no security, and can (in some rare circumstances) actually cause problems. Best to separate your L3 traffic into different L2 domains.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:52.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0