CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-14
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 151
Rep Power: 3
vijayant has an average reputation (10+)
Default Disable antispoofing for a subnet

Hi

Is it possible to disable antispoofing for a preticular subnet behind internal interface, letting it remain enabled for rest of the subnets.
Reply With Quote
  #2 (permalink)  
Old 2008-02-15
Member
 
Join Date: 2008-01-10
Location: Orlando, FL
Posts: 75
Rep Power: 1
rokudan has an average reputation (10+)
Send a message via AIM to rokudan
Default Re: Disable antispoofing for a subnet

See this Thread: Another weird Anti Spoofing Issue
Reply With Quote
  #3 (permalink)  
Old 2008-02-15
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Disable antispoofing for a subnet

vijayant: If you give more details on what you want to achieve it will be a lot easier to healp, what exactly do you mean by "disable antispoofing for a preticular subnet behind internal interface, letting it remain enabled for rest of the subnets?"
Reply With Quote
  #4 (permalink)  
Old 2008-02-15
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 151
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: Disable antispoofing for a subnet

MarioL

I was just curious if this is possible or not.

Scenario:

Let network A, B, C, D be behind Internal Interface. And Antispoofing enabled on Internal and External interfaces. Now to prevent traffic from being blocked by antispoofing we need to creat a Group and add A, B, C, D to that group and mention this in internal interface Topology.
Now I want that traffic from Network C should not be checked for antispoofing. Can we do that..
Reply With Quote
  #5 (permalink)  
Old 2008-02-16
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: Disable antispoofing for a subnet

Quote:
Originally Posted by vijayant View Post
MarioL

I was just curious if this is possible or not.

Scenario:

Let network A, B, C, D be behind Internal Interface. And Antispoofing enabled on Internal and External interfaces. Now to prevent traffic from being blocked by antispoofing we need to creat a Group and add A, B, C, D to that group and mention this in internal interface Topology.
Now I want that traffic from Network C should not be checked for antispoofing. Can we do that..
Dont think so... antispoof is a simple on and off setting only... put it this way.. can we do an x-ray and look at our lung without looking at our heart which is soo close to it??

Theres no way we can define that in anti-spoof network in the interface to check on x networks and not y networks...
Reply With Quote
  #6 (permalink)  
Old 2008-02-16
Senior Member
 
Join Date: 2006-05-24
Location: India
Posts: 151
Rep Power: 3
vijayant has an average reputation (10+)
Default Re: Disable antispoofing for a subnet

chuachongchee

thanks !! atleast now i dont have any confusion...
Reply With Quote
  #7 (permalink)  
Old 2008-02-16
Senior Member
 
Join Date: 2007-09-17
Location: Singapore
Posts: 161
Rep Power: 2
chuachongchee has an average reputation (10+)
Default Re: Disable antispoofing for a subnet

Quote:
Originally Posted by vijayant View Post
chuachongchee

thanks !! atleast now i dont have any confusion...
hehe... no problems!... took me a while and some problems to think and try it out too...
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 23:57.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0