Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

AntiSpoofing

How does the FortiOS 2.8 handle anti-spoofing ? Is it possible to control this feature from the CLI ?
5 REPLIES 5
Not applicable

FortiOS does not have anti-spoofing. It uses interface-based policies (from LAN to DMZ for example). These interfaces are configured through the firewall rules and yes - you can do this from the CLI. - Zedd
Not applicable

I does have antispoofing... Not like Checkpoint but it does. Unlike checkpoint you also set the incoming interface and the outgoing interface in a rule (fe internal to external). In that sence if you have a rule allow 10.0.0.0/24 all all from in to ext this network cannot be spoofed as the attacker has to be comming from the int interface. This is antispoofing functionality! Also you can prevent IP spoofing with IP MAC binding feature. but Be aware that also MACs can nowdays be spoofed.
Not applicable

In FortiOS, anti-spoofing is based on IP routing, not FW policy. And also anit-spoofing is not configurable.
Not applicable

A fortigate inspects for every packet that arrives at an interface the reverse routing path.... So the fortigate does *know* about anti spoofing.
UkWizard
New Contributor

wow, so many ways to say the exact same thing ...
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors