Enabling IP spoofing attack defense on the USG6000 series

The USG6000 looks up the routing table for the outgoing interfaces of reverse traffic destined to the source. If the incoming interface of the traffic and the outgoing interface of the reverse traffic are different, the packets are considered IP spoofing packets and discarded.
Run the firewall defend ip-spoofing enable command to enable IP spoofing attack defense.

