CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-20
Junior Member
 
Join Date: 2006-11-14
Posts: 12
Rep Power: 0
Dom c has an average reputation (10+)
Default Another weird Anti Spoofing Issue

Got another weird anti spoofing issue...

We have an interface set up as 172.19.1.113/22, traffic destined for this /22 network passes except 172.19.1.128/27 which is dropped by anti spoofing.
This network is not defined anywhere else on the firewall in the routing or topology..
Any ideas ??
Cheers
Reply With Quote
  #2 (permalink)  
Old 2007-09-20
Senior Member
 
Join Date: 2007-06-04
Posts: 1,071
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Another weird Anti Spoofing Issue

It's not part of a remote encryption domain is it ?
Reply With Quote
  #3 (permalink)  
Old 2007-09-20
Junior Member
 
Join Date: 2006-11-14
Posts: 12
Rep Power: 0
Dom c has an average reputation (10+)
Default Re: Another weird Anti Spoofing Issue

Alas no, there is no other reference to that range..
I have taken support on this issue and the person that configured it is not in this week.
I think in the intial setup, the interface may have been configured wrong and this /27 has been bound in the kernel somewhere.
I will try and get an outage to reboot the system and hope that clears it..
Reply With Quote
  #4 (permalink)  
Old 2007-09-20
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 153
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: Another weird Anti Spoofing Issue

Maybe it is defined at some other object.

quick search:
Code:
cd $FWDIR/conf
grep 172.19.1 objects_5_0.C
Reply With Quote
  #5 (permalink)  
Old 2008-01-10
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 151
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: Another weird Anti Spoofing Issue

Hi

Please check the Route on the Firewall module if it is routed to some other interface
Reply With Quote
  #6 (permalink)  
Old 2008-01-11
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Another weird Anti Spoofing Issue

If I was you I'd double check the logs, make sure what interface is dropping the traffic, etc. Maybe there is a routing problem somewhere.
Reply With Quote
  #7 (permalink)  
Old 2008-01-11
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: Another weird Anti Spoofing Issue

In topology > Edit Interface > Topology Tab.... Have you setup a group of objects behind that interface? If not create a group for that interface, and add the IP's/Networks of what is behind it...

Reply With Quote
  #8 (permalink)  
Old 2008-02-16
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: Another weird Anti Spoofing Issue

Quote:
Originally Posted by rokudan View Post
In topology > Edit Interface > Topology Tab.... Have you setup a group of objects behind that interface? If not create a group for that interface, and add the IP's/Networks of what is behind it...

This happens with 3rd party clusters...

In cluster objects, in NGAI versions we can do "Get Interfaces", in NGX for 3rd party clusters its "get interfaces with topology". This will check the interfaces as well as defined routes as well, it will create the antispoof for you, if you have only one network, it will be "internal", specific <network>.. If you have some defined static routes, it will create a group object for you and define antispoof automatically.. all this happens in the background without you even knowing it.. if you have very presice of whats inside the smartdashboard... take a look in the network n group objects.. see if theres any new "rouge" objects created.. like net_10.1.1.0_1 etc.. usually a tell tale sign.. or search for overlapping/duplicate objects using the query objects function...

What i did was to detach both cluster members, remove or properly define all interfaces manually and add them back to the cluster again, then DO MANUALLY the cluster interfaces... reconfigure antispoof manually if needed...


Hope this helps... Please remember to backup your configuration b4 any change such as this...

Last edited by chuachongchee; 2008-02-16 at 09:28.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:30.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0