<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site2Site Routing and default route in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-Routing-and-default-route/m-p/112039#M15530</link>
    <description>&lt;P&gt;What do the routes look like when you set them via Next Hop Logical?&lt;BR /&gt;Highly encourage a TAC case here.&lt;/P&gt;</description>
    <pubDate>Mon, 01 Mar 2021 05:32:36 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-03-01T05:32:36Z</dc:date>
    <item>
      <title>Site2Site Routing and default route</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-Routing-and-default-route/m-p/111502#M15413</link>
      <description>&lt;P&gt;Hi all.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm struggling with a weird situation.&lt;/P&gt;&lt;P&gt;I've inherited a network.&lt;BR /&gt;1 Dc, 1 DR, 10 remote sites.&lt;BR /&gt;DC + DR has a 3 FWs cluster (15600), and each remote site has 2 FWs cluster (3200).&lt;BR /&gt;We have 2 separate L2 connections between all sites, and Site2Site IPSec VPN on top of that.&lt;/P&gt;&lt;P&gt;Each remote site has static routes as follows:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;set static-route default nexthop gateway address &amp;lt;DC Cluster VIP - SDH1&amp;gt; on
set static-route default nexthop gateway address &amp;lt;DC Cluster VIP - SDH2&amp;gt; on
set static-route &amp;lt;FW MGMT network&amp;gt; nexthop gateway address &amp;lt;DC Cluster VIP - SDH1&amp;gt; priority 2 on
set static-route &amp;lt;FW MGMT network&amp;gt; nexthop gateway address &amp;lt;DC Cluster VIP - SDH2&amp;gt; priority 1 on&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The DCs has the following static routes to the remote sites:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;set static-route &amp;lt;Remote FW network - Internal&amp;gt; nexthop gateway address &amp;lt;Remote Cluster VIP - SDH1&amp;gt; priority 2 on
set static-route &amp;lt;Remote FW network - Internal&amp;gt; nexthop gateway address &amp;lt;Remote Cluster VIP - SDH2&amp;gt; priority 1 on
set static-route &amp;lt;Remote FW 1 - Internal&amp;gt; nexthop gateway address &amp;lt;Remote Cluster VIP - SDH1&amp;gt; priority 4 on
set static-route &amp;lt;Remote FW 1 - Internal&amp;gt; nexthop gateway address &amp;lt;Remote Cluster VIP - SDH2&amp;gt; priority 3 on
set static-route &amp;lt;Remote FW 2 - Internal&amp;gt; nexthop gateway address &amp;lt;Remote Cluster VIP - SDH1&amp;gt; priority 4 on
set static-route &amp;lt;Remote FW 2 - Internal&amp;gt; nexthop gateway address &amp;lt;Remote Cluster VIP - SDH2&amp;gt; priority 3 on&lt;/LI-CODE&gt;&lt;P&gt;The DCs also has a &lt;STRONG&gt;default&lt;/STRONG&gt; route that points to our partners DC.&lt;/P&gt;&lt;P&gt;Once I remove this default route i lose all communication the the LANs in my remote sites.&lt;/P&gt;&lt;P&gt;If I do one of the following:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;1. Add a default route to our backbone (he does only L2, and has one IP for management).&lt;BR /&gt;2. Add a static route for each remote site with "next hop logical".&lt;/P&gt;&lt;P&gt;everything is working.&lt;/P&gt;&lt;P&gt;I've read and reread all the relevant info I could find, but I still don't get it...&lt;/P&gt;&lt;P&gt;Any insights?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Feb 2021 12:52:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-Routing-and-default-route/m-p/111502#M15413</guid>
      <dc:creator>eliadr</dc:creator>
      <dc:date>2021-02-22T12:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site Routing and default route</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-Routing-and-default-route/m-p/112039#M15530</link>
      <description>&lt;P&gt;What do the routes look like when you set them via Next Hop Logical?&lt;BR /&gt;Highly encourage a TAC case here.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 05:32:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-Routing-and-default-route/m-p/112039#M15530</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-01T05:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site Routing and default route</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-Routing-and-default-route/m-p/112386#M15600</link>
      <description>&lt;P&gt;I only did some tests with it, but haven't implemented it network-wide.&lt;BR /&gt;I thought I'm missing something in the manuals\guides\BPs...&lt;/P&gt;&lt;P&gt;Anyway, it looked like that (at the DC FWs - the branches remained unchanged):&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;set static-route &amp;lt;Remote site internal network&amp;gt; nexthop gateway logical bond1.&amp;lt;SDH1 VLAN&amp;gt; on
set static-route &amp;lt;Remote site internal network&amp;gt; nexthop gateway logical bond1.&amp;lt;SDH2 VLAN&amp;gt; on&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm also trying to open a case with Checkpoint, but I'm dependent on my retailer...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for trying to help.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 15:29:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-Routing-and-default-route/m-p/112386#M15600</guid>
      <dc:creator>eliadr</dc:creator>
      <dc:date>2021-03-03T15:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site Routing and default route</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-Routing-and-default-route/m-p/112404#M15602</link>
      <description>&lt;P&gt;Unless I am not getting it, it looks like your backbone by default does not share CAM tables universally.&lt;/P&gt;
&lt;P&gt;So when you add the default route, to the management IP, there is probably arp cache being populated that is accessible to all.&lt;/P&gt;
&lt;P&gt;When you are doing "next hop logical", you are just throwing the packets out of the interface without requiring knowledge of the peer's MAC addresses.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Mar 2021 20:13:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-Routing-and-default-route/m-p/112404#M15602</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-03-03T20:13:22Z</dc:date>
    </item>
    <item>
      <title>Re: Site2Site Routing and default route</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-Routing-and-default-route/m-p/120858#M17167</link>
      <description>&lt;P&gt;So, apparently it was some misunderstanding on our side of how and when VPN routing\regular routing happens.&lt;BR /&gt;It wasn't clear enough for us from the documentation.&lt;BR /&gt;Also, now I see, my description above wasn't accurate enough - sorry about that...&lt;/P&gt;&lt;P&gt;In short, we had routes from the DCs FWs only to the branches FWs subnets.&lt;BR /&gt;We added static routes to all other internal subnets in each branch, and it worked.&lt;BR /&gt;TAC explained that there has to be a regular routing decision first, and only then VPN routing kicks in and take precedence.&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 15:15:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site2Site-Routing-and-default-route/m-p/120858#M17167</guid>
      <dc:creator>eliadr</dc:creator>
      <dc:date>2021-06-10T15:15:47Z</dc:date>
    </item>
  </channel>
</rss>

