When enabled, the anti-spoofing option drops packets containing invalid source IP addresses. Trellix IPS determines the validity of a source IP address by comparing it against a configured list of internal networks. Thus, as a pre-requisite, you must define CIDR blocks for every internal network that will send traffic through the Sensor interface in question. Without a comprehensive set of CIDR blocks defined, especially if outbound anti-spoofing is enabled, Trellix IPS may block valid packets.
Anti-spoofing is available only for Sensors in inline mode.
How Trellix IPS determines the validity of a packet depends directly on the direction of that packet:
Inbound — When a packet arrives on the outside interface, its source IP address is compared to the CIDR blocks associated with the interface. If the source IP address of the inbound packet matches one of the CIDR blocks, the packet is considered spoofed and dropped.
Outbound — When a packet arrives on the inside interface, its source IP address is compared to the CIDR blocks associated with the interface. If the source IP address of the outbound packet does not match one of the CIDR blocks, the packet is considered spoofed and dropped.