sk181768 - Anti-Spoofing drops packets that arrive at a Security Gateway through interfaces with Topology "External"

Anti-Spoofing drops packets that arrive at a Security Gateway through interfaces with Topology "External"

Product: ClusterXL, ElasticXL, Maestro HyperScale Firewall, Scalable Chassis, Security Gateways, VSNext, VSX (Traditional)

Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82

OS: Gaia

Last Modified: 2025-11-27

Symptoms

Cause

To calculate the topology of external interfaces, the Anti-Spoofing protection takes all IP addresses configured on the Security Gateway interfaces and excludes the IP addresses assigned to interfaces with the topology other than "External".

If there are routes configured for internal interfaces that overlap with routes configured for external interfaces, then the Anti-Spoofing protection treats the external interfaces as internal.

Example for IPv4:

  1. eth0 - an external interface that has a route for a "larger" network 10.0.0.0/8
  2. eth2 - an internal interface that has a route for a "smaller" network 10.0.0.0/16

Solution

We're here for you

NOTE: This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: Advanced
Status: Approved by TAC
Date Created: 2023-12-11
Last Modified: 2025-11-27