<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Anti Spoofing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anti-spoofing/m-p/1448434#M67040</link>
    <description>&lt;P&gt;I have an AIP-SSM-20 module that I am in the process of upgrading the system images and the signatures.&lt;/P&gt;&lt;P&gt;I was wondering if someone could guide me in the right direction on how to configure an anti-spoofing policy on the sensor.&lt;/P&gt;&lt;P&gt;If you have some sample configs that I could look at or even if you can explain to me how to do it through the GUI I would really appreciate it.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:02:43 GMT</pubDate>
    <dc:creator>cdetirado</dc:creator>
    <dc:date>2019-03-10T12:02:43Z</dc:date>
    <item>
      <title>Anti Spoofing</title>
      <link>https://community.cisco.com/t5/network-security/anti-spoofing/m-p/1448434#M67040</link>
      <description>&lt;P&gt;I have an AIP-SSM-20 module that I am in the process of upgrading the system images and the signatures.&lt;/P&gt;&lt;P&gt;I was wondering if someone could guide me in the right direction on how to configure an anti-spoofing policy on the sensor.&lt;/P&gt;&lt;P&gt;If you have some sample configs that I could look at or even if you can explain to me how to do it through the GUI I would really appreciate it.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:02:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anti-spoofing/m-p/1448434#M67040</guid>
      <dc:creator>cdetirado</dc:creator>
      <dc:date>2019-03-10T12:02:43Z</dc:date>
    </item>
    <item>
      <title>Re: Anti Spoofing</title>
      <link>https://community.cisco.com/t5/network-security/anti-spoofing/m-p/1448435#M67045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you mean Anti-IP spoofing -&lt;/P&gt;&lt;P&gt;then it's typically applied on routing devices (firewalls, routers, L3 switches) and not on the firewall.&lt;/P&gt;&lt;P&gt;Unicast RPF is your friend on ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Jul 2010 23:37:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anti-spoofing/m-p/1448435#M67045</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-07-02T23:37:37Z</dc:date>
    </item>
    <item>
      <title>Re: Anti Spoofing</title>
      <link>https://community.cisco.com/t5/network-security/anti-spoofing/m-p/1448436#M67049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Carlos,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It depends on what type of attack you are attempting to protect against. RPF will help you when a host spoofs an address on an interface where it should not live. For instance, if your internal network is 192.168.1.0/24 and a packet arrives on the outside of your firewall with a source address of 192.168.1.2, the appliance can drop the packet due to the information in its routing table. However, SYN floods from the Internet are a different matter. There is a mechanism on the IPS that can help you with this. Please see the document below for the SYN Cookie functionality of IPS Signature 3050/0.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-11874"&gt;https://supportforums.cisco.com/docs/DOC-11874&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;BR /&gt;Blayne Dreier&lt;BR /&gt;Cisco TAC IDS Team&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**Please check out our Podcast**&lt;BR /&gt;&lt;SPAN&gt;TAC Security Show: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/go/tacsecuritypodcast"&gt;http://www.cisco.com/go/tacsecuritypodcast&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Jul 2010 21:46:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anti-spoofing/m-p/1448436#M67049</guid>
      <dc:creator>Christopher Dreier</dc:creator>
      <dc:date>2010-07-04T21:46:05Z</dc:date>
    </item>
  </channel>
</rss>

