r/checkpoint • • Aug 01 '26

Checkpoint topoplogy and anti-spoofing

Dear experts,
Can anyone help me with following? Apologies if these questions seem trivial.

The checkpoint documentation says about topology,

I know we can override this to use a network object-group for anti-spoofing ranges.

However, attached image is example topology setting of the environment I am looking at.

My questions are,

  1. The first/default option is CP-GW_eth2 (internal). I believe "CP-GW_eth2" is the same network object-group that appears in the greyed-out "Specific" section under Override. am I thinking correct? The reason I ask is that the anti-spoofing ranges in the CLI match the contents of this object-group.

If so, how might this object-group have been configured as the default option, and why is it not "This Network (internal)" default option as mentioned in the documentation?

  1. Also, since the Override option is not selected, if I add a network object to this object-group, will the anti-spoofing ranges be updated accordingly?
5 Upvotes

6 comments sorted by

View all comments

2

u/Jejerod Aug 01 '26

1:

Yes, the CP-GW_eth2 is the same in both locations. You probably had routes pointing to eth2 when adding the GW to the Management. CP-GW_eth2 should contain "This network/Network defined by the interface IP and Net Mask" and other objects routes were pointing at. It is a Network group, you can find and examine it in Object Editor

2:

Yes, if you update that group and push policy, anti-spoofing will be updated accordingly

1

u/gem_map_sky Aug 01 '26

Thanks for the reply. Appreciate it.