CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-12-12
HighTeq HighTeq is offline
Junior Member
 
Join Date: 2005-12-12
Location: San Jose
Posts: 5
Rep Power: 0
HighTeq has an average reputation (10+)
Send a message via Yahoo to HighTeq
Default External/Internal Interfaces

When I do the initial install of NGX express and define the IP's on the interfaces via Nokia Voyager they both show as External interfaces within SmartDashboard for the Firewall object. What am I missing????
Reply With Quote
  #2 (permalink)  
Old 2005-12-12
alienbaby alienbaby is offline
Junior Member
 
Join Date: 2005-11-25
Posts: 17
Rep Power: 0
alienbaby has an average reputation (10+)
Default Re: External/Internal Interfaces

Do you have multiple default gateways defined?
Reply With Quote
  #3 (permalink)  
Old 2005-12-12
HighTeq HighTeq is offline
Junior Member
 
Join Date: 2005-12-12
Location: San Jose
Posts: 5
Rep Power: 0
HighTeq has an average reputation (10+)
Send a message via Yahoo to HighTeq
Default Re: External/Internal Interfaces

I just have the default gateway set on the inside address (192.168.x.x) interface.
Reply With Quote
  #4 (permalink)  
Old 2005-12-12
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: External/Internal Interfaces

You can change the setting in Dashboard to be Internal if that is what it is, rather than external. You should only have the interfaces that are external marked as external.

I'm curious as to why you have a default route set on your internal network through. Normally it should be pointing out to your ISP router.
Reply With Quote
  #5 (permalink)  
Old 2005-12-13
HighTeq HighTeq is offline
Junior Member
 
Join Date: 2005-12-12
Location: San Jose
Posts: 5
Rep Power: 0
HighTeq has an average reputation (10+)
Send a message via Yahoo to HighTeq
Default Re: External/Internal Interfaces

This is the problem I am experiencing. The Internal interface option is grayed out within the SmartDashboard on all 3 interfaces (WAN, LAN, and DMZ). Once I make the firewall 'Live' I will be moving the default gateway to my ISP.
Reply With Quote
  #6 (permalink)  
Old 2005-12-14
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: External/Internal Interfaces

I have never seen the Internal interface option greyed out. Can you provide a screenshot?
Reply With Quote
  #7 (permalink)  
Old 2005-12-14
HighTeq HighTeq is offline
Junior Member
 
Join Date: 2005-12-12
Location: San Jose
Posts: 5
Rep Power: 0
HighTeq has an average reputation (10+)
Send a message via Yahoo to HighTeq
Default Re: External/Internal Interfaces

Here you go. This is the LAN interface properties you are seeing.
Attached Images
File Type: jpg Checkpoint.JPG (28.5 KB, 584 views)
Reply With Quote
  #8 (permalink)  
Old 2005-12-14
HighTeq HighTeq is offline
Junior Member
 
Join Date: 2005-12-12
Location: San Jose
Posts: 5
Rep Power: 0
HighTeq has an average reputation (10+)
Send a message via Yahoo to HighTeq
Default Re: External/Internal Interfaces

Boy do I feel stupid. I have resolved this issue. The Checkpoint object was defined as a host rather then a gateway object. Converting it to a gateway object obviously now allows me to define the interfaces. Sometimes we overlook the simplest things.

Thanks for all your help and patience.
Reply With Quote
  #9 (permalink)  
Old 2005-12-14
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: External/Internal Interfaces

Good to hear that you found the problem. I was at a loss as I have never seen that before. It's a good thing to know as I'm sure you are not the only person that will do that.
Reply With Quote
  #10 (permalink)  
Old 2007-04-13
crono_79 crono_79 is offline
Junior Member
 
Join Date: 2006-04-06
Posts: 21
Rep Power: 0
crono_79 has an average reputation (10+)
Default Re: External/Internal Interfaces

god

thanks for posting the solution

i was stomped by the same issue and just got resolved doing what you did

thanks a los
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 17:41.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0