sk181768 - Anti-Spoofing drops packets that arrive at a Security Gateway through interfaces with Topology "External"
Anti-Spoofing drops packets that arrive at a Security Gateway through interfaces with Topology "External"
Product: ClusterXL, ElasticXL, Maestro HyperScale Firewall, Scalable Chassis, Security Gateways, VSNext, VSX (Traditional)
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82
OS: Gaia
Last Modified: 2025-11-27
Symptoms
- Anti-Spoofing drops packets that arrive at a Security Gateway through interfaces with Topology "External".
Cause
To calculate the topology of external interfaces, the Anti-Spoofing protection takes all IP addresses configured on the Security Gateway interfaces and excludes the IP addresses assigned to interfaces with the topology other than "External".
If there are routes configured for internal interfaces that overlap with routes configured for external interfaces, then the Anti-Spoofing protection treats the external interfaces as internal.
Example for IPv4:
- eth0 - an external interface that has a route for a "larger" network 10.0.0.0/8
- eth2 - an internal interface that has a route for a "smaller" network 10.0.0.0/16
Solution
We're here for you
NOTE: This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: Advanced
Status: Approved by TAC
Date Created: 2023-12-11
Last Modified: 2025-11-27