<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Static Route Entry - Appliance vs Full Gaia in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-Route-Entry-Appliance-vs-Full-Gaia/m-p/126267#M18312</link>
    <description>&lt;P&gt;Hi. Currently we have a 1450 appliance in a serviced office. We are going to swap it out for a 4000 appliance. We have 1 internal interface that's the default gateway of the PCs. Its IP is 10.10.10.1. Looking at the routing table, any traffic for the subnet 10.10.10.0/24 is forwarded to the same interface (LAN1; IP 10.10.10.1)&lt;/P&gt;&lt;P&gt;On the full version of Gaia I know if I put in the next hop as 10.10.10.1 I will get an error saying that the IP is already taken by the FW interface. I believe all I need to do is to specify the next hop as an interface and the routing should work (I don't know the IP of the switch downstream). I don't have a means of testing until the migration is in progress - am I thinking along the right lines with this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Aug 2021 16:49:38 GMT</pubDate>
    <dc:creator>Wyman</dc:creator>
    <dc:date>2021-08-10T16:49:38Z</dc:date>
    <item>
      <title>Static Route Entry - Appliance vs Full Gaia</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-Route-Entry-Appliance-vs-Full-Gaia/m-p/126267#M18312</link>
      <description>&lt;P&gt;Hi. Currently we have a 1450 appliance in a serviced office. We are going to swap it out for a 4000 appliance. We have 1 internal interface that's the default gateway of the PCs. Its IP is 10.10.10.1. Looking at the routing table, any traffic for the subnet 10.10.10.0/24 is forwarded to the same interface (LAN1; IP 10.10.10.1)&lt;/P&gt;&lt;P&gt;On the full version of Gaia I know if I put in the next hop as 10.10.10.1 I will get an error saying that the IP is already taken by the FW interface. I believe all I need to do is to specify the next hop as an interface and the routing should work (I don't know the IP of the switch downstream). I don't have a means of testing until the migration is in progress - am I thinking along the right lines with this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 16:49:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-Route-Entry-Appliance-vs-Full-Gaia/m-p/126267#M18312</guid>
      <dc:creator>Wyman</dc:creator>
      <dc:date>2021-08-10T16:49:38Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Entry - Appliance vs Full Gaia</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-Route-Entry-Appliance-vs-Full-Gaia/m-p/126282#M18316</link>
      <description>&lt;P&gt;In general, yes, you would use the interface as the next hop.&lt;BR /&gt;Is the gateway also going to have an IP on 10.10.10.0/24?&lt;BR /&gt;In which case, that route should not be necessary as it should be added as a result of adding the IP to the interface.&lt;/P&gt;
&lt;P&gt;Which does beg the question what purpose this route is serving.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 20:42:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-Route-Entry-Appliance-vs-Full-Gaia/m-p/126282#M18316</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-10T20:42:53Z</dc:date>
    </item>
    <item>
      <title>Re: Static Route Entry - Appliance vs Full Gaia</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-Route-Entry-Appliance-vs-Full-Gaia/m-p/127106#M18411</link>
      <description>&lt;P&gt;Hi PhoneBoy. Thanks for the reply. Yes, the internal IP of the FW will have the IP of 10.10.10.1/24 so that will be the clients' default gateway.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 15:08:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Static-Route-Entry-Appliance-vs-Full-Gaia/m-p/127106#M18411</guid>
      <dc:creator>Wyman</dc:creator>
      <dc:date>2021-08-16T15:08:20Z</dc:date>
    </item>
  </channel>
</rss>

