zigar, thanks for the link, good info.

I dont have access to my WatchGuard right now to verify but the wording on that sounds like "if you enable it" almost as if its not on by default. If it is on it sounds like it may prevent the attack.

Although I wonder if in theory my original statement would work if IP spoofing protection was turned off.

My hangup is:
Firewall IPS say = BLOCK THAT SCAN AND SITE!
VPN policy says = create trusted network connection between sites

Not sure if one would override the other is malicious activity was spotted.