| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Hello Folks, This should be pretty easy but I'm a bit rusty. I have a Nokia FW, 190 with 3 Interfaces. Inside, DMZ and Outside. Currently each only has one subnet and everything is working fine. The Inside interface obviously plugs into a switch. The Inside LAN segment is, 192.168.10.0. I am adding/configuring inter-vlan Layer 3 switching on my switch. I want to also add a new subnet behind the switch. Inside subnet = 192.168.10.0 / New subnet = 10.10.0.0. Topology is set for Inside at 192.168.10.0. I create the new VLAN on my switch. Host DG = Switch for specific VLAN ID. Switch DG = FW. 0.0.0.0/24 next hop = 192.168.10.1 The 10 net hosts can ping the 192.168.10.0 net and vise versa. 192 net can go out to the Internet. But the 10 net cannot go out of the FW...getting address spoofing. Where do I add/configure that subnet as an internal LAN or let the FW know about it. Where do I configure the address spoofing for the new subnet? I will be adding more, so this is the test. Also, I will need to add a route on the Nokia for Source = outside Dst = Inside for the new subnets right? AS I have 3 site-site VPN's. thanks...BirdDog Last edited by BirdDog; 2007-10-18 at 15:23. |
| |||
| Too much information. Just go into the topology overview of the related checkpoint object. select the interface behind which these other networks are located at. click on edit. select the second tab. select internal interface and the network group that also contains your old as well as your new networks. install policy. |
| |||
| For routing you just need to add static routes that point to the new internal subnets, and use the switch as the gateway address. Once that is done then you can either just create a group and place the internal networks in that group and then under topology for the internal interface set to be specific and then specify the group. Alternatively you can just do a get interfaces with topology on the gateway object after adding the routes and it will automatically create the topology config based on the routing table. |
![]() |
| Thread Tools | |
| Display Modes | |
| |