CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Windows
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-04-23
dav_y2k dav_y2k is offline
Junior Member
 
Join Date: 2007-04-09
Posts: 12
Rep Power: 0
dav_y2k has an average reputation (10+)
Default Number of subnets Checkpoint supports

Hi all,

Please I'd like to know the total number of subnets Checkpoint NGX R65 (and SecurePlatform as well) supports on both Windows and Unix like platform. Does this depends on the number of interfaces each Hardware platform supports? I know the Windows hardware supports 32 interfaces.

thanks in advance
Reply With Quote
  #2 (permalink)  
Old 2007-04-24
dav_y2k dav_y2k is offline
Junior Member
 
Join Date: 2007-04-09
Posts: 12
Rep Power: 0
dav_y2k has an average reputation (10+)
Default Re: Number of subnets Checkpoint supports

Hi all,
I have another question which is, I have a network as shown in the diagram attached. This is the scenario, I have a checkpoint NGX R60 (which will be upgraded to NGX R65, the third-party network was formerly connected directly to the private LAN using an old router. I would like to connect this third-party network (which are separate subnets) to the firewall I would like to know:
1) Do I need to configure a vlan, if so do I need to add a layer 3 switch before the firewall?
2) would I need to configure NAT/static routes on the Checkpoint firewall?
3) I would also like to add a separate server for a schedule backup using veritas, is there any security concerns?
Any advice/input is welcomed or links to tutorials.

Thanks in advance.
Attached Images
File Type: jpg ntwk_lay.JPG (29.9 KB, 135 views)

Last edited by dav_y2k; 2007-04-24 at 09:11.
Reply With Quote
  #3 (permalink)  
Old 2007-04-25
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 375
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: Number of subnets Checkpoint supports

If they are separate entities you should keep them apart, using vlans or even separate interfaces. If it's the same entity you can use subinterfaces on the firewall, one for each network and that will work. Mind to put all 3 networks on the anti-spoofing though.
Reply With Quote
  #4 (permalink)  
Old 2007-04-25
dav_y2k dav_y2k is offline
Junior Member
 
Join Date: 2007-04-09
Posts: 12
Rep Power: 0
dav_y2k has an average reputation (10+)
Default Re: Number of subnets Checkpoint supports

Thanks MarioL. Some of the entities are separate. and if I want to create vlans does checkpoint support inter-vlan communication or do I need a layer 3 switch (if so where do I place it)?
Reply With Quote
  #5 (permalink)  
Old 2007-04-25
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Number of subnets Checkpoint supports

Quote:
Originally Posted by dav_y2k View Post
Thanks MarioL. Some of the entities are separate. and if I want to create vlans does checkpoint support inter-vlan communication or do I need a layer 3 switch (if so where do I place it)?
If you want the FW to inspect the traffic, then you do not want to use the routing features of a layer 3 switch and let the FW route the traffic.

Remember in its normal configuration a Check Point Firewall gateway is a router.
Reply With Quote
  #6 (permalink)  
Old 2007-04-25
dav_y2k dav_y2k is offline
Junior Member
 
Join Date: 2007-04-09
Posts: 12
Rep Power: 0
dav_y2k has an average reputation (10+)
Default Re: Number of subnets Checkpoint supports

Thanks Chillyjim,
what do I need to configure virtual interfaces on the firewall (if so please could you kindly give me a link as to how to do this) or what do I need to do on the firewall?

Last edited by dav_y2k; 2007-04-25 at 19:01.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:26.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0