Modifying anti-spoofing
IP address spoofing is an attack where the source IP address in a packet is changed to gain unauthorized access or to cause a denial-of-service. Such attacks can be prevented with anti-spoofing rules.
Anti-spoofing prevents malicious attempts to use legitimate internal IP addresses to gain unauthorized access from lower-security to higher-security networks. It does this by validating source addresses against the networks connected to each interface.
If an interface receives a packet with an invalid source address for its connected networks, the packet is identified as coming from a spoofed IP address.
Anti-spoofing is used on Engines, Master Engines, and Virtual Engines. Anti-spoofing rules are created automatically based on the routing configuration for interfaces that have IP addresses. In most cases, there is no need to change the anti-spoofing configuration in any way.
If you modify the anti-spoofing configuration, manually changed entries are marked with a plus sign (+) for active entries or a minus sign (–) for disabled entries.
Limitations
Anti-spoofing cannot be configured for the following types of interfaces because they do not have IP addresses:
- Capture Interfaces and Inline Interfaces
- Master Engines
- Layer 2 physical interfaces on Engines.