SV-228844r557387_rule
V-228844
SRG-NET-000192-ALG-000121
PANW-AG-000050
CAT II
10
Create an anti-spoofing policy for each outgoing zone that drops any traffic when the source IP does not match the list of allowed IP ranges for each outgoing zone.
Navigate to the “Zone Protection Profile” configuration screen.
Select the “Packet- Based Attack Protection” tab.
Select the “IP Drop” tab.
Check the “Spoofed IP Address” box.
Verify an anti-spoofing policy is configured for each outgoing zone that drops any traffic when the source IP does not match the list of allowed IP ranges for each outgoing zone.
Navigate to the “Zone Protection Profile” configuration screen
Select the “Packet-Based Attack Protection” tab
Select the “IP Drop” tab
If the “Spoofed IP Address” box is not checked for each outgoing zone, this is a finding.
V-228844
False
PANW-AG-000050
Verify an anti-spoofing policy is configured for each outgoing zone that drops any traffic when the source IP does not match the list of allowed IP ranges for each outgoing zone.
Navigate to the “Zone Protection Profile” configuration screen
Select the “Packet-Based Attack Protection” tab
Select the “IP Drop” tab
If the “Spoofed IP Address” box is not checked for each outgoing zone, this is a finding.
M
4233