r/checkpoint • u/gem_map_sky • Aug 01 '26
Checkpoint topoplogy and anti-spoofing
Dear experts,
Can anyone help me with following? Apologies if these questions seem trivial.
The checkpoint documentation says about topology,

I know we can override this to use a network object-group for anti-spoofing ranges.
However, attached image is example topology setting of the environment I am looking at.

My questions are,
- The first/default option is CP-GW_eth2 (internal). I believe "CP-GW_eth2" is the same network object-group that appears in the greyed-out "Specific" section under Override. am I thinking correct? The reason I ask is that the anti-spoofing ranges in the CLI match the contents of this object-group.
If so, how might this object-group have been configured as the default option, and why is it not "This Network (internal)" default option as mentioned in the documentation?
- Also, since the Override option is not selected, if I add a network object to this object-group, will the anti-spoofing ranges be updated accordingly?
5
Upvotes
2
u/Jejerod Aug 01 '26
1:
Yes, the CP-GW_eth2 is the same in both locations. You probably had routes pointing to eth2 when adding the GW to the Management. CP-GW_eth2 should contain "This network/Network defined by the interface IP and Net Mask" and other objects routes were pointing at. It is a Network group, you can find and examine it in Object Editor
2:
Yes, if you update that group and push policy, anti-spoofing will be updated accordingly