| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| I have a CP R55 AI on SPLAT. got a new IP block from ISP. (Not necessary to do ISP redundancy, just want more public IP for NAT). I put the 2 routers onto the same external switch. On SPLAT, I added eth0:1 as secondary external IP, added a new default gateway with matric value 20. Now I can see eth0:1 in SPLAT sysconfig, but can not detect it through GUI fw, get interface with topology. My question is: since I can retrieve the virtual interface topology, do I have to add a NIC instead of virtual IP(eth0:1)? TIA Last edited by fraserchen; 2008-01-28 at 13:10. |
| |||
| Update: Tested a solution as following, it works. 1)add a new external interface 2)install load sharing ISP redundancy Comments: 1)the 2nd default gateway with matric 20 was removed automatically after I installed ISP redundancy policy. 2)If I disable ISP redundancy, enable 2nd default gateway(ISP-2) with matric value, the NAT address I configured for the new IP block doesn't work because FW still forwards the response to ISP-1, the default gateway. fraser __________________ rgds, fraser |
| |||
| Update 2: Instead of ISP redundancy, I tried to put secondary IP on external interface to represent new ip block and failed. after I configured secondary IP and secondary default gateway IP, everything seems fine. then I login to FW GUI, could not GET the secondary IP from fw object. then I manually added the IP and choose it to be external Interface. After I installed this policy, fw detected the ISP-2 interface down immediately. Even if I was able to ping the ISP-2 gateway IP. __________________ rgds, fraser |
![]() |
| Thread Tools | |
| Display Modes | |
| |