<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: disable Spoof detection Inside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/disable-spoof-detection-inside/m-p/1061139#M895902</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;had spoof off on the interfaces, there was no Ip verify reverse-path. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok here was the problem, I had static routes on the pix that pointed to subnets on the inside that were not present on my lab router. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example, I had route to 192.168.99.7 but no 192.168.99.0/24 subnet.  I created a loopback interface with that subnet and the spoofs that the pix was reporting to 99.7 went away.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems a guy in another thread had a similar problem but he didn't have a default route set for his outside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once I went into my lab router and created loopbacks with the 3 subnets that were being spoofed, all spoof attacking ceased. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 26 Sep 2008 14:00:30 GMT</pubDate>
    <dc:creator>dmooreami</dc:creator>
    <dc:date>2008-09-26T14:00:30Z</dc:date>
    <item>
      <title>disable Spoof detection Inside</title>
      <link>https://community.cisco.com/t5/network-security/disable-spoof-detection-inside/m-p/1061137#M895900</link>
      <description>&lt;P&gt;Have a pix 515e in lab running 7.0x code. It is flooding me with Ip spoof messages. how do I disable Ip spoof detection on the inside interface. The addresses it claims are being spoofed are GRE tunnel endpoints that need to pass thru the pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have this config running in production and don't get any spoof messages&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:49:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-spoof-detection-inside/m-p/1061137#M895900</guid>
      <dc:creator>dmooreami</dc:creator>
      <dc:date>2019-03-11T13:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: disable Spoof detection Inside</title>
      <link>https://community.cisco.com/t5/network-security/disable-spoof-detection-inside/m-p/1061138#M895901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Run :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run | in ip verify&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should see :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip verify reverse-path interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do a " no "...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no ip verify reverse-path interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this does not help,maybe you can post the exact log message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sushil&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2008 13:33:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-spoof-detection-inside/m-p/1061138#M895901</guid>
      <dc:creator>suschoud</dc:creator>
      <dc:date>2008-09-26T13:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: disable Spoof detection Inside</title>
      <link>https://community.cisco.com/t5/network-security/disable-spoof-detection-inside/m-p/1061139#M895902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;had spoof off on the interfaces, there was no Ip verify reverse-path. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok here was the problem, I had static routes on the pix that pointed to subnets on the inside that were not present on my lab router. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Example, I had route to 192.168.99.7 but no 192.168.99.0/24 subnet.  I created a loopback interface with that subnet and the spoofs that the pix was reporting to 99.7 went away.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems a guy in another thread had a similar problem but he didn't have a default route set for his outside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once I went into my lab router and created loopbacks with the 3 subnets that were being spoofed, all spoof attacking ceased. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Sep 2008 14:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-spoof-detection-inside/m-p/1061139#M895902</guid>
      <dc:creator>dmooreami</dc:creator>
      <dc:date>2008-09-26T14:00:30Z</dc:date>
    </item>
  </channel>
</rss>

