CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-04-15
Junior Member
 
Join Date: 2008-04-15
Posts: 6
Rep Power: 0
jsmwalker has an average reputation (10+)
Default Extending Subnet

Hi,

Before I go much further I have only just started using Checkpoint, used to Cisco and various other firewalls, but struggling a little with this, basically we have our internal LAN set us 192.168.139.0 (255.255.255.0) However we are running short of IP's, so thought an easy answer would be to change subnet to 255.255.254.0 which should then cover 192.168.138.0 - 192.168.139.255, although the checkpoint accepts this, anything on the 192.168.138.0-255 range does not get any connection through the firewall.

Any ideas? We are running NGX R60

J
Reply With Quote
  #2 (permalink)  
Old 2008-04-15
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 582
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: Extending Subnet

Quote:
Originally Posted by jsmwalker View Post
Hi,

Before I go much further I have only just started using Checkpoint, used to Cisco and various other firewalls, but struggling a little with this, basically we have our internal LAN set us 192.168.139.0 (255.255.255.0) However we are running short of IP's, so thought an easy answer would be to change subnet to 255.255.254.0 which should then cover 192.168.138.0 - 192.168.139.255, although the checkpoint accepts this, anything on the 192.168.138.0-255 range does not get any connection through the firewall.

Any ideas? We are running NGX R60

J
Have you updated the topology on the object representing your Security Gateway after changing the underlying topology?
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
  #3 (permalink)  
Old 2008-04-15
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Extending Subnet

Also make sure you have updated the "inside network" object so that it is hiding the 192.168.138.0/23 network and not just the 192.168.139.0/24 network.
Reply With Quote
  #4 (permalink)  
Old 2008-04-16
Junior Member
 
Join Date: 2008-04-15
Posts: 6
Rep Power: 0
jsmwalker has an average reputation (10+)
Default Re: Extending Subnet

Hi

Thanks for that, ok what I have changed is the subnet on the interface, and also the internal LAN network address, however I think you maybe onto something, when I go to get Topology on Interfaces it returns still 192.168.139.0 255.255.255.0 not 255.255.254.0, however I have no idea how to update this....

J
Reply With Quote
  #5 (permalink)  
Old 2008-04-16
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 465
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: Extending Subnet

Quote:
Originally Posted by jsmwalker View Post
Hi

Thanks for that, ok what I have changed is the subnet on the interface, and also the internal LAN network address, however I think you maybe onto something, when I go to get Topology on Interfaces it returns still 192.168.139.0 255.255.255.0 not 255.255.254.0, however I have no idea how to update this....

J
Fetch topology/interfaces gather interfaces as they are configured in the OS.
Have you changed the subnet mask on the actual interface (network connection) in the operating system? If no, do that and it will fetch it correctly. If you already did that, then cpstop cpstart can sometimes solve this and then get topoligy/interface via smartdashboard again.
Reply With Quote
  #6 (permalink)  
Old 2008-04-16
Junior Member
 
Join Date: 2008-04-15
Posts: 6
Rep Power: 0
jsmwalker has an average reputation (10+)
Default Re: Extending Subnet

Excellent, forgot there is an underlying OS, all done and working.

Cheers for that.

J
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 23:50.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0