- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-01-2013 06:17 AM
Dear,
We have created a zone protection profile with protection against "Spoofed IP address".
We have put this protection profile on a vwire interface.
Question:
What will happen since a vwire interface has no IPs?
Will this "feature" be ignored, or what will happen / how can we configure this to apply the protection?
KR
08-01-2013 07:34 AM
No Mr.linus,
that would break the concept of using a vwire. but I would recommend converting the vwire interfaces to layer 3 interfaces, unless there is a company norm for you to use vwire interfaces.
Best regards,
Karthik RP
08-01-2013 06:29 AM
Hi Linus,
As the vwire interfaces dont have an IP address, they wouldnt be subjected to IP spoofed attacks. But if you want to protect the servers behind the vwire interfaces, you can deploy a DoS Protection policy with a DoS protection profile, which includes protection for the IP spoof attacks as well.
Best regards,
Karthik
08-01-2013 06:56 AM
Hi Linus,
I just verified that the DoS Protection profile doesnt support checking for Spoofed IPs. The firewall can detect an IP address as being spoofed, if it sees the packet on a different interface than the one for which it has learnt the route for. As there is no routing information per se on the vwire interfaces, the PANFW, ignores the route checks for the source and the destination IP addresses, and hence ignores the IP spoof check for these packets.
BR,
Karthik RP
08-01-2013 07:20 AM
seems logical, but is there a way we can add IP information to the vwires so we can use this feature?
I know that when we create sub-vwire-interfaces we can use classifiers, would this be an option?
08-01-2013 07:34 AM
No Mr.linus,
that would break the concept of using a vwire. but I would recommend converting the vwire interfaces to layer 3 interfaces, unless there is a company norm for you to use vwire interfaces.
Best regards,
Karthik RP
08-01-2013 07:43 AM
Alright, thanks for the info.
08-01-2013 12:43 PM
Would it?
Cant you through zones define which networks are expected on which end of the vwire?
Perhaps it needs a feature request similar to how vwire filters 802.1Q tagged vlans.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!