> Source: [sk126832](https://support.checkpoint.com/results/sk/sk126832)

# sk126832 - Traffic, arriving over VPN that terminates on an external interface, is dropped for address spoofing once traffic decrypted

| Property | Value |
|----------|-------|
| Solution ID | sk126832 |
| Date Created | 2018-06-08 |
| Last Modified | 2026-09-02 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20 |
| OS | Gaia |

## Symptoms

- Traffic, arriving over VPN that terminates on an external interface, is then dropped for address spoofing once the traffic is decrypted.  


See error message: "x.x.x.x:5060 dropped by fw_antispoof_log Reason: Address spoofing;"

## Cause

When the relevant IP address has been defined under the topology section of an internal interface, then it is only expected and accepted on that internal interface.

It will then be dropped on the external interface, once the traffic is decrypted from the VPN connection.

## Solution

Ensure that any IP address, or IP address range that is expected to arrive on the external interface over a VPN tunnel is not included in any topology (or topology group object) that is defined for an internal interface.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1526266754393/topology object1805132014.png)

**Note:** This issue can occur in situations where NAT is disabled in the VPN configuration and private IP addresses are being used in the traffic flow. Upon the decryption of the traffic, instead of being forwarded for routing, the packets are dropped for address spoofing since the relevant IP address is defined to only be expected on the relevant internal address.

**Alternative:** If the Anti-Spoofing settings cannot be modified to exclude the internal network from an external network's topology, add an Anti-Spoofing exception by checking "Don't check packets from..." and adding an object with the relevant network address.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
