CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > NAT (Network Address Translation)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-06-13
pvtjoker27 pvtjoker27 is offline
Junior Member
 
Join Date: 2006-06-08
Posts: 5
Rep Power: 0
pvtjoker27 has an average reputation (10+)
Default Multiple registered subnets, one ext interface

Need some help on this -

We have a deployment that is moving 3 registered subnets (formerly on 3 different FW's with 2 ext facing interfaces) to 3 registered subnets on a single NGX cluster.

Let's call the registered nets: 64.x.x.x (the subnet the ext interface of the CP is on), 191.x.x.x and 11.x.x.x.

The incoming "pipes" are aggregated via a fatpipe warp device - this device has 3 logical interfaces which connect via one physical interface to a switch - this is the switch which our single IPSO/CP NGX R60 external interface will connect.

We have internal devices that need to statically map to addresses on all three registered subnets. On our old FW solution, this wasn't a problem - it recieved a request for an address on the 191, 64 or 11 and simply passed it along to the internal host that was specified.

My question is this - does Checkpoint behave the same way?If I create a static NAT entry for an internal host, can it be on any of the three registered subnets, or does it have to be on the ext interface subnet (64.x.x.x)? Will the automatic functions cover the arp issues?

If not - any clues as to how to do this?
Reply With Quote
  #2 (permalink)  
Old 2006-09-20
RobertGraham RobertGraham is offline
Senior Member
 
Join Date: 2006-02-02
Posts: 204
Rep Power: 3
RobertGraham has an average reputation (10+)
Send a message via MSN to RobertGraham Send a message via Yahoo to RobertGraham
Default Re: Multiple registered subnets, one ext interface

As long as you register one IP from each network on the external interface, it should be possible to do exactly what you need.

However, I don't know about using the fatpipe device you speak of. You might have problems getting Check Point to realize that one interface is on three different networks. Is it safe to guess that you can't supernet them?
Reply With Quote
  #3 (permalink)  
Old 2006-09-27
theoracle theoracle is offline
Junior Member
 
Join Date: 2006-09-27
Posts: 12
Rep Power: 0
theoracle has an average reputation (10+)
Default Re: Multiple registered subnets, one ext interface

It should work fine with your 3 registered addresses. The arp issues are handled transparently by the Checkpoint modules.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 14:07.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0