Hi,I need some help on a problem with Anti-spoofing feature. I have a Checkpoint VPN module, with two NIC cards. One card is connected to a DMZ and the other is connected to a internal network. Because the internal network AND Internet (External) can access this VPN module via the DMZ NIC, I have disable the Anti-Spoofing on the DMZ interface; without this, Internal communication with MngMT console not work. I cant stop traffic comming from internal network to the VPN NIC. So what I want to do is a group with EXTERNAL object and INTERNAL object so i can activate the anti-spoof to remove the warning errors I get when installing rules.But EXTERNAL object not exist. Any know what i can do?
Im not quite clear on your topology. What do you mean the internet and the internal nets access the gateway through the dmz interface? If theres only 2 nics, 1 is internal and 1 is external (even if it is going to private addresses) or am I missing something?