| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hi all, I use Crossbeam X40 + Checkpoint Provider-1. Today, I have a problem when I configure ip address + subnet mask in Checkpoint. 1. If I configure big subnet 202.78.225.128/25 in Checkpoint Provider-1, only subnet from 202.78.225.192/26 can connect to Internet, ip addresss between 202.78.225.128/25 to 202.78.225.192/26 can't connect to Internet. 2. If I configure subnet 202.78.225.128/27, it can connect to Internet 3. If I configure subnet 202.78.225.160/27, it can connect to Internet . If you understand about ip address in Checkpoint, please answer me. Thank you very much. If you have any question, please ask me. |
| |||
| Are you configuring a network object or what? Where is this object used? /25 isn't big. I've got a coule of /23's. What version of P-1 and HFA level are you using? Ray |
| |||
| So you're changing the interface on the crossbeam, or are you just creating a network object and making a security rule so it can access the internet? And your first problem is you're running Crossbeam. The more my company uses Crossbeams, the more I want to go to the PIX side of the house. Anyway, did you check flow rules, etc. Have you run a fw monitor while trying to connect? |
| |||
| Quote:
Is it Crossbeam og CheckPoint that causes the pain ? |
| |||
| Quote:
We use C and X series, along with Nokia. I haven't really had to deal with Solaris, although we still have a couple around. For me, Nokia has been by far the easiest. C-series isn't too bad, it's just that problems keep coming up. Like losing static routes when they're pointed to vlans. Or making a change on the system parameters and it causes /etc/hosts to change the mgmt ip 127.0.0.1. If it was up to the admins, we'd be working on Nokia. We don't make buying decisions though. I did go to a Crossbeam class and really liked the instructor, I just think it's too new of a product right now for our environment. They can talk about performance all they want, but if it's causing issues, I don't care what kind of throughput you get. |
| |||
| Quote:
Admin forgot to add dynamic_objects to a firewall and all traffic was dropped when policy was pushed. On Nokia, traffic is fine without dynamic_objects (although it can cause issues on Nokia, it's been rare). |
![]() |
| Thread Tools | |
| Display Modes | |
| |