CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-04-15
Junior Member
 
Join Date: 2006-09-08
Posts: 15
Rep Power: 0
endrps2 has an average reputation (10+)
Default Add Subnet R61 splat

Hi, I have a splat r61 working perfect. all the IP's are real (no Nat),autonomous system.
The dmz subnet is eth2 192.111.60.0 255.255.255.192
The lan subnet is eth1 192.111.61.0 255.255.255.0
The out subnet is eth0 192.111.60.64 255.255.255.240

My lan pool are almost out of ip addresses and i need more ip's for more workstation to add. the subnet have 192.111.61.0 255.255.255.0 which is 254ip's.

I have one more class c in my pool (right now not in use) - 192.111.63.0 255.255.255.0

what and how to config the R61 splat to enable internet connection for a workstation in the lan that will have ip address from the new pool 192.111.63.0 255.255.255.0 ? all work station are connect to the same lan (no vlan or router).
Attached Images
File Type: jpg firewall.jpg (74.1 KB, 124 views)
Reply With Quote
  #2 (permalink)  
Old 2007-04-15
Member
 
Join Date: 2006-11-03
Posts: 37
Rep Power: 0
inetd has an average reputation (10+)
Default Re: Add Subnet R61 splat

Routing 101 says you gotta have a gateway on that subnet in order to route that traffic. You can create vlan interfaces or sub interfaces with the appropriate IP addresses assigned. In your situation you might want to introduce NAT into the equation.
Reply With Quote
  #3 (permalink)  
Old 2007-04-15
Junior Member
 
Join Date: 2006-09-08
Posts: 15
Rep Power: 0
endrps2 has an average reputation (10+)
Default Re: Add Subnet R61 splat

Hi, do you mean that i have to add one more nic to the splat?
Reply With Quote
  #4 (permalink)  
Old 2007-04-16
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Add Subnet R61 splat

You can add a different IP to the internal interface, no additional NIC needed.

A shame that the subnets are not contiguous, otherwise you could just supernet them.
Reply With Quote
  #5 (permalink)  
Old 2007-04-16
Junior Member
 
Join Date: 2006-09-08
Posts: 15
Rep Power: 0
endrps2 has an average reputation (10+)
Default Re: Add Subnet R61 splat

What do you mean "subnets are not contiguous"
can you give example of contiguous subnets?

is splat r61 support sub interface?
Reply With Quote
  #6 (permalink)  
Old 2007-04-16
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Add Subnet R61 splat

If you had 192.111.60.0/24 available you could "supernet" this one with the 192.111.61.0/24, by changing the netmask to be /23.

So 192.111.60.0/23 (using net mask 255.255.254.0) would have 512 addresses, 510 of which usable. 62 and 63 could also be "superneted" together, etc

SPLAT supports sub interface yes.
Reply With Quote
  #7 (permalink)  
Old 2007-04-16
Junior Member
 
Join Date: 2006-09-08
Posts: 15
Rep Power: 0
endrps2 has an average reputation (10+)
Default Re: Add Subnet R61 splat

I tried to add a different IP to the internal interface.
befor adding the new ip
run ifconfig -a

eth0 192.111.60.69 255.255.255.240 etc...
eth1 192.111.61.1 255.255.255.0 etc...
eth2 192.111.60.1 255.255.255.192 etc...

after add new ip to the internal interface
run ip config -a

eth0 192.111.60.69 255.255.255.240 etc...
eth1 192.111.61.1 255.255.255.0 etc...
eth1:0 192.111.63.1 255.255.255.0 etc...
eth2 192.111.60.1 255.255.255.192 etc...

after the ip was added to eth1:0 running the command
fw ctl iflist

0 : eth0
1 : eth1
2 : eth2

now i need to configure the gateway interface topology in the dashboard.
the eth1:0 (new interface) is not supported and not appear.
how to configure the topology to work with the new subnet?
Reply With Quote
  #8 (permalink)  
Old 2007-04-18
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 159
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: Add Subnet R61 splat

You have to use a group for this topo.

1) create a group for example name firewallname_eth1
2) create the network objects (if not present) for 192.111.61.0/24 and 192.111.63.0/24
3) put the network objects in the group
4) configure the antispoofing for eth1 to use this group

If you have sk access:
Solution ID: 55.0.4270321.2607685 - Setting up virtual interfaces on VPN-1/FireWall-1
sk27369: Adding virtual IP address on SecurePlatform interfaces

as alternative for eth1:x use a small transfer network and a fast layer 3 switch build the group for the network objects and route with the switch
Reply With Quote
  #9 (permalink)  
Old 2007-04-19
Junior Member
 
Join Date: 2006-09-08
Posts: 15
Rep Power: 0
endrps2 has an average reputation (10+)
Default Re: Add Subnet R61 splat

Done. work perfect
Thank you all
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 09:15.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0