> Source: [sk180814](https://support.checkpoint.com/results/sk/sk180814)

# sk180814 - Anti-Spoofing drops traffic on the Security Gateway interface that connects to the Internet

| Property | Value |
|----------|-------|
| Solution ID | sk180814 |
| Date Created | 2023-04-04 |
| Last Modified | 2023-04-10 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- Anti-Spoofing drops traffic on the Security Gateway interface that connects to the Internet.

Anti-Spoofing drops traffic that arrives from all sources except the interface's subnet.

## Cause

The Topology of this interface in the Security Gateway object is configured as "Override \> This Network (Internal) \> Network defined by routes".

This Topology configuration is intended only for interfaces that are connected to internal networks behind the Security Gateway.

By design, when the Topology is defined by routes on a Security Gateway interface, the Anti-Spoofing protection accepts traffic only from the source subnet, from which an IP address was assigned to this interface. The Anti-Spoofing protection drops traffic from all other source IP addresses on this interface.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
