System
Properties>Advanced>Anti-Spoofing
The Anti-Spoofing panel allows you to specify which interfaces to protect from an IP
spoofing
attack using
network ingress and egress filtering.
The following sections are included in this Help topic:
Important Notes
●
Field Descriptions
●
Enabling or Disabling Anti-Spoofing on an interface
●
Resetting to Last Applied Settings
●
Important Notes
This feature provides Unicast
RPF
(Reverse Path Forwarding) functionality for the PIX Firewall and is disabled
by default. Due to the danger of IP spoofing in the IP protocol, measures need to be taken to reduce this risk when
possible. Unicast RPF, or reverse route lookups, prevents such manipulation under certain circumstances.
Caution: Before using this feature, add static routes for every network that can be accessed on the interfaces you
wish to protect. Only enable this feature if routing is fully specified. Otherwise, the PIX Firewall will stop traffic
on the interface you specify if routing is not in place.
Field Descriptions
The Anti-Spoofing panel displays the following fields:
Interface check boxes—Select this check box to enable anti-spoofing on that interface for your device.
Clicking any check box again will clear anti-spoofing on that interface. The number and labels of these
boxes will depend on the model of PIX Firewall in use.
●
Apply to PIX—Applies changes you have made to the PIX Firewall.
●
Reset—Discards any changes without applying them.
●
Enabling or Disabling Anti-Spoofing on an Interface
To enable or disable anti-spoofing, follow these steps:
Select the appropriate check boxes for the interface or interfaces on which you would like to enable
1.
Summary of Contents for PIX 520 - PIX Firewall 520
Page 45: ...Copyright 2001 Cisco Systems Inc ...
Page 68: ...Copyright 2001 Cisco Systems Inc ...
Page 74: ...Copyright 2001 Cisco Systems Inc ...
Page 87: ...Copyright 2001 Cisco Systems Inc ...
Page 92: ...Copyright 2001 Cisco Systems Inc ...
Page 108: ......
Page 184: ......
Page 197: ...Copyright 2001 Cisco Systems Inc ...
Page 200: ......
Page 232: ...Copyright 2001 Cisco Systems Inc ...
Page 246: ...Copyright 2001 Cisco Systems Inc ...