CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-01-28
fraserchen fraserchen is offline
Junior Member
 
Join Date: 2007-04-26
Posts: 5
Rep Power: 0
fraserchen has an average reputation (10+)
Default new IP block and secondary IP

I have a CP R55 AI on SPLAT. got a new IP block from ISP. (Not necessary to do ISP redundancy, just want more public IP for NAT).

I put the 2 routers onto the same external switch. On SPLAT, I added eth0:1 as secondary external IP, added a new default gateway with matric value 20.

Now I can see eth0:1 in SPLAT sysconfig, but can not detect it through GUI fw, get interface with topology.

My question is:
since I can retrieve the virtual interface topology, do I have to add a NIC instead of virtual IP(eth0:1)?

TIA

Last edited by fraserchen; 2008-01-28 at 13:10.
Reply With Quote
  #2 (permalink)  
Old 2008-01-29
fraserchen fraserchen is offline
Junior Member
 
Join Date: 2007-04-26
Posts: 5
Rep Power: 0
fraserchen has an average reputation (10+)
Default Re: new IP block and secondary IP

Update:

Tested a solution as following, it works.
1)add a new external interface
2)install load sharing ISP redundancy

Comments:
1)the 2nd default gateway with matric 20 was removed automatically after I installed ISP redundancy policy.

2)If I disable ISP redundancy, enable 2nd default gateway(ISP-2) with matric value, the NAT address I configured for the new IP block doesn't work because FW still forwards the response to ISP-1, the default gateway.

fraser
__________________
rgds,
fraser
Reply With Quote
  #3 (permalink)  
Old 2008-01-29
fraserchen fraserchen is offline
Junior Member
 
Join Date: 2007-04-26
Posts: 5
Rep Power: 0
fraserchen has an average reputation (10+)
Default Re: new IP block and secondary IP

Update 2:

Instead of ISP redundancy, I tried to put secondary IP on external interface to represent new ip block and failed.

after I configured secondary IP and secondary default gateway IP, everything seems fine. then I login to FW GUI, could not GET the secondary IP from fw object. then I manually added the IP and choose it to be external Interface. After I installed this policy, fw detected the ISP-2 interface down immediately. Even if I was able to ping the ISP-2 gateway IP.
__________________
rgds,
fraser
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 19:58.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0