Description
This article describes how to confirm that antispoofing is configured correctly and is operational on the FortiGate.
Scope
All versions of FortiGate.
Solution
Meet the following prerequisites:
show full | grep asym
Example output:
show full | grep asym
set asymroute disable
set asymroute-icmp disable
set asymroute6 disable
set asymroute6-icmp disable
show full | grep src-check
Example output:
show full | grep src-check
set src-check enable
set src-check enable
set src-check enable
set src-check enable
set src-check enable
set strict-src-check disable
diagnose debug reset
diagnose debug flow filter addr x.x.x.x y.y.y.y and
diagnose debug flow trace start 1000
diagnose debug enable
On port10, the subnet 100.65.0.0/16 is configured. However, the PC has an IP of 100.64.0.2. Here is the output when this PC is failing the antispoof check:
See: Technical Tip: Reverse Path Forwarding (RPF) implementation and use of strict-src-check enable|disab... for more information about antispoofing.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.