<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Default gateway beyond network scope in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Default-gateway-beyond-network-scope/m-p/28804#M2271</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Hi team,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Object&lt;/STRONG&gt; : Default gateway beyond network scope&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ios GAIA : 80.10 - VNIC in bridge configuration with ESXi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to&amp;nbsp;implement the following configuration for my WAN interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IP&lt;/STRONG&gt;: 54.39.~.~&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Netmask&lt;/STRONG&gt;: 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Gateway&lt;/STRONG&gt;: 192.99.~.&lt;STRONG&gt;254&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This interface is linked to my ESXi NIC (bridge mode) whose IP address is 192.99.~.~ I tried different solutions to hard-modify interface and routing configuration without effect:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I modify this file:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;/etc/routed0.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I still got:&lt;/P&gt;&lt;P&gt;default gateway eth1 preference &lt;STRONG&gt;192.168.1.1&lt;/STRONG&gt; 192.99....254 preference 1;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also modify&lt;STRONG&gt; /etc/sysconfig/network-scripts/ifcfg-eth1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I do not want to get out by means of pfsense on 192.168.1.1&lt;/STRONG&gt; but with my ESXi interface gateway. I know that this configuration is not a RFC common configuration and had to work hard to find a solution on pfsense ; on pfsense it works now&amp;nbsp; Checkpoint is a RHEL completely modified knowing that it is similar to Quagga. I could put Quagga as an external router but i want to solve this issue. Not a lot of information on the web considering this point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basic commands like this one doesn't work:&lt;/P&gt;&lt;PRE style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;CODE&gt;&lt;CODE&gt;set static-route default nexthop gateway address &lt;EM&gt;&lt;STRONG&gt;&lt;SPAN style="color: #3d3d3d;"&gt;192.99.~.&lt;/SPAN&gt;254&lt;/STRONG&gt;&lt;/EM&gt; priority 1 on&lt;BR /&gt;&lt;SPAN style="background-color: #ffffff; font-weight: 400;"&gt;set static-route default nexthop gateway address&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;192.168.1.1&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; font-weight: 400;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;off&lt;/SPAN&gt;&lt;BR /&gt;&lt;/CODE&gt;&lt;/CODE&gt;save-config&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Gregory&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;First email address:&amp;nbsp;&lt;A href="mailto:gregory.morilleau@alliacom.com"&gt;gregory.morilleau@alliacom.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Second&amp;nbsp;email address: &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:gregory.morilleau@axians.com"&gt;gregory.morilleau@axians.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 22 Sep 2018 19:19:40 GMT</pubDate>
    <dc:creator>Samia_Ferozi</dc:creator>
    <dc:date>2018-09-22T19:19:40Z</dc:date>
    <item>
      <title>Default gateway beyond network scope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Default-gateway-beyond-network-scope/m-p/28804#M2271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Hi team,&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Object&lt;/STRONG&gt; : Default gateway beyond network scope&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ios GAIA : 80.10 - VNIC in bridge configuration with ESXi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to&amp;nbsp;implement the following configuration for my WAN interface:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;IP&lt;/STRONG&gt;: 54.39.~.~&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Netmask&lt;/STRONG&gt;: 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Gateway&lt;/STRONG&gt;: 192.99.~.&lt;STRONG&gt;254&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This interface is linked to my ESXi NIC (bridge mode) whose IP address is 192.99.~.~ I tried different solutions to hard-modify interface and routing configuration without effect:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I modify this file:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;/etc/routed0.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I still got:&lt;/P&gt;&lt;P&gt;default gateway eth1 preference &lt;STRONG&gt;192.168.1.1&lt;/STRONG&gt; 192.99....254 preference 1;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also modify&lt;STRONG&gt; /etc/sysconfig/network-scripts/ifcfg-eth1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I do not want to get out by means of pfsense on 192.168.1.1&lt;/STRONG&gt; but with my ESXi interface gateway. I know that this configuration is not a RFC common configuration and had to work hard to find a solution on pfsense ; on pfsense it works now&amp;nbsp; Checkpoint is a RHEL completely modified knowing that it is similar to Quagga. I could put Quagga as an external router but i want to solve this issue. Not a lot of information on the web considering this point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basic commands like this one doesn't work:&lt;/P&gt;&lt;PRE style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;CODE&gt;&lt;CODE&gt;set static-route default nexthop gateway address &lt;EM&gt;&lt;STRONG&gt;&lt;SPAN style="color: #3d3d3d;"&gt;192.99.~.&lt;/SPAN&gt;254&lt;/STRONG&gt;&lt;/EM&gt; priority 1 on&lt;BR /&gt;&lt;SPAN style="background-color: #ffffff; font-weight: 400;"&gt;set static-route default nexthop gateway address&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;192.168.1.1&lt;/EM&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="background-color: #ffffff; font-weight: 400;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;off&lt;/SPAN&gt;&lt;BR /&gt;&lt;/CODE&gt;&lt;/CODE&gt;save-config&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Gregory&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;First email address:&amp;nbsp;&lt;A href="mailto:gregory.morilleau@alliacom.com"&gt;gregory.morilleau@alliacom.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Second&amp;nbsp;email address: &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:gregory.morilleau@axians.com"&gt;gregory.morilleau@axians.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Sep 2018 19:19:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Default-gateway-beyond-network-scope/m-p/28804#M2271</guid>
      <dc:creator>Samia_Ferozi</dc:creator>
      <dc:date>2018-09-22T19:19:40Z</dc:date>
    </item>
    <item>
      <title>Re: Default gateway beyond network scope</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Default-gateway-beyond-network-scope/m-p/28805#M2272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only supported mechanism to configure static routes in Gaia OS is using the clish commands or via the WebUI.&lt;/P&gt;&lt;P&gt;Hacking the configuration files you are trying to hack is unsupported.&lt;/P&gt;&lt;P&gt;You can only configure a next hop to be either:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;A specific IP address (needs to be on the same subnet)&lt;/LI&gt;&lt;LI&gt;A specific interface&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Have you tried configuring the next hop as a specific interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note that configuring the default route to have a next hop that is an interface (versus a specific IP) will cause the ARP cache to rapidly fill up.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Sep 2018 22:13:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Default-gateway-beyond-network-scope/m-p/28805#M2272</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-22T22:13:29Z</dc:date>
    </item>
  </channel>
</rss>

