CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-15
mdalton mdalton is offline
Junior Member
 
Join Date: 2008-05-14
Posts: 1
Rep Power: 0
mdalton has an average reputation (10+)
Default Adding a static Route to remote network

Hello all… I need to add a route to my NGX R60 (172.18.1.1)

All Nodes in my LAN are 172.18.XXX.XXX 255.255.0.0 GW 172.18.1.1



By a route this is what I mean.



My default Gateway of all LAN nodes is 172.18.1.1, which is my NGX R60. ALLTRAFFIC goes out the Gateway. This can’t and will not be changed.



I now have added a second network, a remote network if you will, this remote network IP scheme is 10.10.10.XXX. To get to that network you need to send the traffic to 172.18.1.250. (A Cisco 1720)



I am assuming I need to create a route statement in the NGX R60 that states all 10.10.10.XXX traffic go to this IP 172.18.1.250, all other traffic out to the internet.



Question? How would I do that, I am not able to add hardware or make any real changes to the cisco, as I believe that this should and can be done inside the NGX R60.



Here is a PDF showing what I am “trying” to do.



http://www.westcoastpc.net/mpls.pdf



172.18.1.250 has been configured to get to 10.10.10.XXX I just to send the traffic that way, currently all traffic goes out to the internet.



Please help, I am dying over here!
Reply With Quote
  #2 (permalink)  
Old 2008-05-15
sebastan_bach sebastan_bach is online now
Senior Member
 
Join Date: 2005-10-12
Posts: 315
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: Adding a static Route to remote network

hi in checkpoint there is no issue in sending the traffic out back of the same interface . so in checkpoint u just need to add a static route for the 10.10.x.x network pointing to the cisco router. rest everything should work fine.

if u are not good with the cli i hope u are using checkpoint splat right. open the gui of the checkpoint. i guess it should be https://172.18.1.1.

in the gui there is a link for network connections just add a route for the 10 network and specify the gateway and the exit interface.

this should do the work.

let me know it doesn;t work out. i will surely try to help u out.

regards

sebastan
Reply With Quote
  #3 (permalink)  
Old 2008-05-16
hotice_ hotice_ is offline
Senior Member
 
Join Date: 2007-06-05
Location: Montreal,Canada
Posts: 152
Rep Power: 2
hotice_ has an average reputation (10+)
Default Re: Adding a static Route to remote network

Pretty straigthforward.

you can also go via command line and use the syscommand ...much faster then the clumsy WebGUI
Reply With Quote
  #4 (permalink)  
Old 2008-05-16
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,637
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Adding a static Route to remote network

Just remember to update your topology or you'll end up with anti-spoofing errors.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 14:43.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0