<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Adding default gateway outside scope of interface in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-default-gateway-outside-scope-of-interface/m-p/6092#M225</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried the scenario in my cloud lab but the routing entry will not stick.&lt;/P&gt;&lt;P&gt;The article does not list R80 and R80.10 and I noticed the indicated file (/etc/routed.conf) does not contain the suggested information.&lt;/P&gt;&lt;P&gt;I have put in a note with the SK to ask if this is a known issue with R80.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As of yet the ISP has not been making a fuss about the routing entry over the interface.&lt;/P&gt;&lt;P&gt;Pending the remark I made on th SK I may create a TAC ticket.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Sep 2017 07:48:12 GMT</pubDate>
    <dc:creator>Hugo_vd_Kooij</dc:creator>
    <dc:date>2017-09-11T07:48:12Z</dc:date>
    <item>
      <title>Adding default gateway outside scope of interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-default-gateway-outside-scope-of-interface/m-p/6088#M221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gents,&lt;/P&gt;&lt;P&gt;I try to setup a lab gateway on my OVH server. But OVH has a rather odd setup.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;External interface has a /32 netmask. For example: 137.1.2.3/32&lt;/LI&gt;&lt;LI&gt;You need to setup a host route to the router (137.1.2.254 in this example) based on the interface.&lt;/LI&gt;&lt;LI&gt;Then you need to setup the default gateway to the router.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The point is that step 1 and step 2 works on GAIA (R80.10 T421) but the 3rd step does give you no error but it will not actually setup the route.&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;set static-route 137.1.2.254/32 nexthop gateway logical eth1 priority 1 on&lt;BR /&gt;set static-route default nexthop gateway address 137.1.2.254 priority 1 on&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Is there a trick to force GAIA to bring up the default gateway?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I change the subnet mask to /24 it work but ...... OVH goes totally balistic if I configure it that way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other trick is to dump the default just on the interface eth1 and that will work as well&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The next step is the wizard. It will not accept this netmask.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did someone work this out with GAIA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can Someone from Check Point R&amp;amp;D get a little bit of budget to toy around on OVH and see if they can fix GAYA to work in such a setup?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Sep 2017 18:56:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-default-gateway-outside-scope-of-interface/m-p/6088#M221</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-09-07T18:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: Adding default gateway outside scope of interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-default-gateway-outside-scope-of-interface/m-p/6089#M222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wouldn't a /32 subnet be a point-to-point interface?&lt;/P&gt;&lt;P&gt;In that case it would seem setting the default route to the interface in question is the correct way to configure this.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Sep 2017 20:26:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-default-gateway-outside-scope-of-interface/m-p/6089#M222</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-07T20:26:49Z</dc:date>
    </item>
    <item>
      <title>Re: Adding default gateway outside scope of interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-default-gateway-outside-scope-of-interface/m-p/6090#M223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The syntax is what I intend. But GAIA simply does not play ball here. It will not setup the default route to a host to which a route has been provided.&lt;/P&gt;&lt;P&gt;And the first time wizard is not even accepting this setting. So I have to work around that limitation too.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 07:30:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-default-gateway-outside-scope-of-interface/m-p/6090#M223</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-09-08T07:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Adding default gateway outside scope of interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-default-gateway-outside-scope-of-interface/m-p/6091#M224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe information on&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92799&amp;amp;partition=Advanced&amp;amp;product=ClusterXL%22"&gt;sk92799&lt;/A&gt;&amp;nbsp;is helpful here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So adding scopelocal might help! This helps in Scenarios where the default-gw is on different subnet than the interface IPs. Like in scenarios where cluster IP is in different subnet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Sep 2017 10:51:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-default-gateway-outside-scope-of-interface/m-p/6091#M224</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2017-09-08T10:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: Adding default gateway outside scope of interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-default-gateway-outside-scope-of-interface/m-p/6092#M225</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried the scenario in my cloud lab but the routing entry will not stick.&lt;/P&gt;&lt;P&gt;The article does not list R80 and R80.10 and I noticed the indicated file (/etc/routed.conf) does not contain the suggested information.&lt;/P&gt;&lt;P&gt;I have put in a note with the SK to ask if this is a known issue with R80.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As of yet the ISP has not been making a fuss about the routing entry over the interface.&lt;/P&gt;&lt;P&gt;Pending the remark I made on th SK I may create a TAC ticket.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 07:48:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-default-gateway-outside-scope-of-interface/m-p/6092#M225</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-09-11T07:48:12Z</dc:date>
    </item>
    <item>
      <title>Re: Adding default gateway outside scope of interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-default-gateway-outside-scope-of-interface/m-p/127589#M18522</link>
      <description>&lt;P&gt;Srry for reviving this ancient topic, but I was wondering if (and how) you eventually &amp;nbsp;managed to solve this particular OVH-lab challenge?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Aug 2021 23:24:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Adding-default-gateway-outside-scope-of-interface/m-p/127589#M18522</guid>
      <dc:creator>nsamsin</dc:creator>
      <dc:date>2021-08-20T23:24:42Z</dc:date>
    </item>
  </channel>
</rss>

