CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-26
rn4it rn4it is offline
Junior Member
 
Join Date: 2005-12-16
Posts: 9
Rep Power: 0
rn4it has an average reputation (10+)
Default Antispoofing error message

I've recently added 2 sites of a business partner to the allow access list for internal users. I've also added these to sites to our DMZ anti-spoof group. For whatever reason these 2 sites are receiving the standard anti-spoof error msg. there are a number of other sites wich are configured to be apart of this group and are working. So why don't these 2, I've checked their IPs, and confirmed a few times that whey were in the group.

any ideas
thanks
John
Reply With Quote
  #2 (permalink)  
Old 2008-05-27
gavvys gavvys is offline
Senior Member
 
Join Date: 2007-04-10
Location: India
Posts: 141
Rep Power: 2
gavvys has an average reputation (10+)
Send a message via Yahoo to gavvys
Default Re: Antispoofing error message

Hi
What logs do you see at the gateway when a request comes from that source.Might be some NAT ip will be coming that is not added in the antispoofing group.Kindly check the logs adn let me know what do u see there for there request.

Regards
Ranjit
Reply With Quote
  #3 (permalink)  
Old 2008-05-27
rn4it rn4it is offline
Junior Member
 
Join Date: 2005-12-16
Posts: 9
Rep Power: 0
rn4it has an average reputation (10+)
Default Re: Antispoofing error message

HI
It's an outgoing request from internal to DMZ, we send it in it's origional state the business partner then NAT's it. We see it being accepted then below it a message stating antispoofing. The weird thing is the rule is set up as follows:

internal net =>businesspartnet(group) allowed service accept log

This rule is working all i should have had to do is add the 2 new hosts into the group. None of these hosts connect into us, it's just us into them.

I'll check the other objects in that group just to see.

thanks
Reply With Quote
  #4 (permalink)  
Old 2008-05-27
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Antispoofing error message

I'd check what interface is generating the logs, maybe the packets aren't being routed properly.
Reply With Quote
  #5 (permalink)  
Old 2008-05-27
rn4it rn4it is offline
Junior Member
 
Join Date: 2005-12-16
Posts: 9
Rep Power: 0
rn4it has an average reputation (10+)
Default Re: Antispoofing error message

Thanks, but traceroutes show they're getting onto the DMZ switch. However, I still check what the logs show.

Any other thoughts if it's not that?
thanks
Reply With Quote
  #6 (permalink)  
Old 2008-05-28
rn4it rn4it is offline
Junior Member
 
Join Date: 2005-12-16
Posts: 9
Rep Power: 0
rn4it has an average reputation (10+)
Default Re: Antispoofing error message

routing is correct and it's the DMZ interface that's reporting the anti-spoofing msg.

Any other ideas? Any way of debuging it? It's CP NG-AI R54 build 243 on an IPSO 3.7 IP530.

thanks
Reply With Quote
  #7 (permalink)  
Old 2008-05-28
rn4it rn4it is offline
Junior Member
 
Join Date: 2005-12-16
Posts: 9
Rep Power: 0
rn4it has an average reputation (10+)
Default Re: Antispoofing error message

This has been resolved, there was a typo on a static route of the DMZ switch, so the traffic was bouncing back to the firewall.

thanks for you assistance.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 06:28.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0