<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Permitting internet on multiple networks in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151196#M24638</link>
    <description>&lt;P&gt;Have a &lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/VLAN-Interfaces.htm" target="_self"&gt;look on this&lt;/A&gt; and you should get the ideea how things are done.&lt;/P&gt;
&lt;P&gt;Also some &lt;A href="https://www.youtube.com/results?search_query=checkpoint+vlan+configuration" target="_self"&gt;youtube videos&lt;/A&gt;, you can start from there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Roughly, you get 2 or more interfaces in a bond, and on the bond you define the Vlans(sub-interfaces) .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;</description>
    <pubDate>Sat, 18 Jun 2022 21:12:12 GMT</pubDate>
    <dc:creator>Sorin_Gogean</dc:creator>
    <dc:date>2022-06-18T21:12:12Z</dc:date>
    <item>
      <title>Permitting internet on multiple networks</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151193#M24635</link>
      <description>&lt;P&gt;I have two vlans on my network, vlan 2 of 10.201.0.0/16 and vlan 3 of 10.50.0.0/24, however, traffic on vlan 2 on which the LAN (eth0) interface is directly connected to can access internet and vlan 3 which is added to (eth0) as an alias with the IP address on the 10.50.0.0/24 network is not accessing internet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the vlan 3 network, on the checkpoint, I cannot ping any client machine on the same network, however from the switch directly connected to the checkpoint firewall can ping the firewall and from firewall and computers on vlan 2 can ping each other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have permitted/accepted all traffic on both networks on 10.201.0.0/16 and 10.50.0.0/24 to &amp;nbsp;any/internet. but when I ping 8.8.8.8 from a computer on vlan 3, I get an error of "address spoofing". see the image of the error log attached .&lt;/P&gt;&lt;P&gt;I will appreciate your support on this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jun 2022 20:35:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151193#M24635</guid>
      <dc:creator>dahlinkj</dc:creator>
      <dc:date>2022-06-18T20:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Permitting internet on multiple networks</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151194#M24636</link>
      <description>&lt;P&gt;why do you have an alias?&lt;/P&gt;
&lt;P&gt;If two vlans are connected to the same physical interface then it should be two logical interfaces connected to a trunk. So when you do a topo update it should only see (as an example)&amp;nbsp; eth0.2 &amp;amp; eth0.3.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jun 2022 20:39:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151194#M24636</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2022-06-18T20:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: Permitting internet on multiple networks</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151195#M24637</link>
      <description>&lt;P&gt;Hello genisis&lt;/P&gt;&lt;P&gt;Thanks for a prompt response, actually I would appreciate if you can share with me a tutorial on how to configure vlans or two logical interfaces on one interface connected to a trunk. I did configure an alias because I didn't know exactly what to do.&amp;nbsp;&lt;/P&gt;&lt;P&gt;much appreciated for your guide.&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jun 2022 20:46:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151195#M24637</guid>
      <dc:creator>dahlinkj</dc:creator>
      <dc:date>2022-06-18T20:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Permitting internet on multiple networks</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151196#M24638</link>
      <description>&lt;P&gt;Have a &lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/VLAN-Interfaces.htm" target="_self"&gt;look on this&lt;/A&gt; and you should get the ideea how things are done.&lt;/P&gt;
&lt;P&gt;Also some &lt;A href="https://www.youtube.com/results?search_query=checkpoint+vlan+configuration" target="_self"&gt;youtube videos&lt;/A&gt;, you can start from there.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Roughly, you get 2 or more interfaces in a bond, and on the bond you define the Vlans(sub-interfaces) .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;</description>
      <pubDate>Sat, 18 Jun 2022 21:12:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151196#M24638</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-06-18T21:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: Permitting internet on multiple networks</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151215#M24642</link>
      <description>&lt;P&gt;Thanks Sorin, you gave me a hint and later on the error :&amp;nbsp;&lt;SPAN&gt;address spoofing , was able to resolve it by disabling the spoofing option on the networks.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jun 2022 20:34:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151215#M24642</guid>
      <dc:creator>dahlinkj</dc:creator>
      <dc:date>2022-06-19T20:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Permitting internet on multiple networks</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151223#M24643</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/54321"&gt;@dahlinkj&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;glad to be of help, still disabling Spoofing is not a GOOD option....&lt;/P&gt;
&lt;P&gt;I would look into making Spoofing groups that we attach to the interfaces, and we manage that; or look into define the spoofing based on routing.&lt;/P&gt;
&lt;P&gt;disabling Spoofing is not OK...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you,&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 06:24:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151223#M24643</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-06-20T06:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: Permitting internet on multiple networks</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151224#M24644</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/31932"&gt;@Sorin&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will appreciate &amp;nbsp;if you can share any info on this , best practice .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 06:46:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Permitting-internet-on-multiple-networks/m-p/151224#M24644</guid>
      <dc:creator>dahlinkj</dc:creator>
      <dc:date>2022-06-20T06:46:07Z</dc:date>
    </item>
  </channel>
</rss>

