CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-02
mylove142 mylove142 is offline
Member
 
Join Date: 2006-08-22
Posts: 58
Rep Power: 3
mylove142 has an average reputation (10+)
Default Urgent!about configure subnet mask in Checkpoint Provider-1

Hi all,
I use Crossbeam X40 + Checkpoint Provider-1. Today, I have a problem when I configure ip address + subnet mask in Checkpoint.

1. If I configure big subnet 202.78.225.128/25 in Checkpoint Provider-1, only subnet from 202.78.225.192/26 can connect to Internet, ip addresss between 202.78.225.128/25 to 202.78.225.192/26 can't connect to Internet.

2. If I configure subnet 202.78.225.128/27, it can connect to Internet

3. If I configure subnet 202.78.225.160/27, it can connect to Internet .

If you understand about ip address in Checkpoint, please answer me.

Thank you very much.

If you have any question, please ask me.
Reply With Quote
  #2 (permalink)  
Old 2007-02-03
RayPesek RayPesek is offline
Senior Member
 
Join Date: 2006-03-19
Location: Northern Ohio
Posts: 876
Rep Power: 3
RayPesek has an average reputation (10+)
Default Re: Urgent!about configure subnet mask in Checkpoint Provider-1

Are you configuring a network object or what? Where is this object used?

/25 isn't big. I've got a coule of /23's.

What version of P-1 and HFA level are you using?

Ray
Reply With Quote
  #3 (permalink)  
Old 2007-02-05
mylove142 mylove142 is offline
Member
 
Join Date: 2006-08-22
Posts: 58
Rep Power: 3
mylove142 has an average reputation (10+)
Default Re: Urgent!about configure subnet mask in Checkpoint Provider-1

I use Crossbeam X40 + Checkpoint Provider 1 R55.
Reply With Quote
  #4 (permalink)  
Old 2007-02-14
dfwboiler dfwboiler is offline
Junior Member
 
Join Date: 2007-01-21
Posts: 18
Rep Power: 0
dfwboiler has an average reputation (10+)
Default Re: Urgent!about configure subnet mask in Checkpoint Provider-1

So you're changing the interface on the crossbeam, or are you just creating a network object and making a security rule so it can access the internet?

And your first problem is you're running Crossbeam. The more my company uses Crossbeams, the more I want to go to the PIX side of the house.

Anyway, did you check flow rules, etc.
Have you run a fw monitor while trying to connect?
Reply With Quote
  #5 (permalink)  
Old 2007-02-14
sail4fun sail4fun is offline
Member
 
Join Date: 2006-07-16
Posts: 44
Rep Power: 0
sail4fun has an average reputation (10+)
Default Re: Urgent!about configure subnet mask in Checkpoint Provider-1

Quote:
Originally Posted by dfwboiler View Post
...

And your first problem is you're running Crossbeam. The more my company uses Crossbeams, the more I want to go to the PIX side of the house.

...
? Why ? , we are using both -x and -c ,(Nokia and Solaris as well) is

Is it Crossbeam og CheckPoint that causes the pain ?
Reply With Quote
  #6 (permalink)  
Old 2007-02-15
dfwboiler dfwboiler is offline
Junior Member
 
Join Date: 2007-01-21
Posts: 18
Rep Power: 0
dfwboiler has an average reputation (10+)
Default Re: Urgent!about configure subnet mask in Checkpoint Provider-1

Quote:
Originally Posted by sail4fun View Post
? Why ? , we are using both -x and -c ,(Nokia and Solaris as well) is

Is it Crossbeam og CheckPoint that causes the pain ?
It's most definately Crossbeam causing the issue. We joke that we're Crossbeam's testing dept.
We use C and X series, along with Nokia. I haven't really had to deal with Solaris, although we still have a couple around.

For me, Nokia has been by far the easiest. C-series isn't too bad, it's just that problems keep coming up. Like losing static routes when they're pointed to vlans. Or making a change on the system parameters and it causes /etc/hosts to change the mgmt ip 127.0.0.1.

If it was up to the admins, we'd be working on Nokia. We don't make buying decisions though.

I did go to a Crossbeam class and really liked the instructor, I just think it's too new of a product right now for our environment. They can talk about performance all they want, but if it's causing issues, I don't care what kind of throughput you get.
Reply With Quote
  #7 (permalink)  
Old 2007-02-15
dfwboiler dfwboiler is offline
Junior Member
 
Join Date: 2007-01-21
Posts: 18
Rep Power: 0
dfwboiler has an average reputation (10+)
Default Re: Urgent!about configure subnet mask in Checkpoint Provider-1

Quote:
Originally Posted by sail4fun View Post
? Why ? , we are using both -x and -c ,(Nokia and Solaris as well) is

Is it Crossbeam og CheckPoint that causes the pain ?
And another thing. While this was more admin error...
Admin forgot to add dynamic_objects to a firewall and all traffic was dropped when policy was pushed.
On Nokia, traffic is fine without dynamic_objects (although it can cause issues on Nokia, it's been rare).
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 00:08.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0