<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configure Public IP address directly on a server behind Checkpoint in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152415#M25404</link>
    <description>&lt;P&gt;Having public address on only the external interface cannot achieve this if the objective is not to use NAT.&lt;/P&gt;
&lt;P&gt;The vendor of Firewall doesn't matter in this context.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the existing DMZ have/use public addresses (Y/N)?&lt;/P&gt;
&lt;P&gt;Yes - Connect the Mitel here with an IP from that subnet.&lt;/P&gt;
&lt;P&gt;No - You will likely have to create a new DMZ involving networking/routing changes &amp;amp; possibly requesting extra or new IP addresses from your ISP.&lt;/P&gt;</description>
    <pubDate>Wed, 06 Jul 2022 08:43:45 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2022-07-06T08:43:45Z</dc:date>
    <item>
      <title>Configure Public IP address directly on a server behind Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152295#M25377</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;We are in process of implementing Mitel MiCollab and the requirement is the WAN interface of the Micollab server should have public ip assigned directly on it. NATting from public ip to private ip does not support.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;MiCollab server is a VM behind the Checkpoint.&lt;/P&gt;&lt;P&gt;How could I achieve this setup with Checkpoint?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 04:58:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152295#M25377</guid>
      <dc:creator>kenn2000</dc:creator>
      <dc:date>2022-07-05T04:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Public IP address directly on a server behind Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152311#M25382</link>
      <description>&lt;P&gt;setup a DMZ&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 08:19:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152311#M25382</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-05T08:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Public IP address directly on a server behind Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152323#M25386</link>
      <description>&lt;P&gt;As Val has hinted another interface/VLAN from the Check Point addressed with the public subnet and configuration pertinent for a DMZ.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 10:13:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152323#M25386</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-05T10:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Public IP address directly on a server behind Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152386#M25401</link>
      <description>&lt;P&gt;Thank you all for your comments.&lt;/P&gt;&lt;P&gt;Sorry I am new to Checkpoint so needing your help further.&lt;/P&gt;&lt;P&gt;We currently have DMZ with a different subnet.&lt;/P&gt;&lt;P&gt;All public IPs have been forwarded to External on a bond Interface.&lt;/P&gt;&lt;P&gt;So I don't know how another DMZ network/Interface will work as what would be the IP address/subnet for them?. What I am understanding is each Interface should have a different subnet.&lt;/P&gt;&lt;P&gt;Could you please help explaining further?&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 00:29:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152386#M25401</guid>
      <dc:creator>kenn2000</dc:creator>
      <dc:date>2022-07-06T00:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Public IP address directly on a server behind Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152415#M25404</link>
      <description>&lt;P&gt;Having public address on only the external interface cannot achieve this if the objective is not to use NAT.&lt;/P&gt;
&lt;P&gt;The vendor of Firewall doesn't matter in this context.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does the existing DMZ have/use public addresses (Y/N)?&lt;/P&gt;
&lt;P&gt;Yes - Connect the Mitel here with an IP from that subnet.&lt;/P&gt;
&lt;P&gt;No - You will likely have to create a new DMZ involving networking/routing changes &amp;amp; possibly requesting extra or new IP addresses from your ISP.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 08:43:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152415#M25404</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-06T08:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Public IP address directly on a server behind Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152437#M25410</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Having public address on only the external interface cannot achieve this if the objective is not to use NAT.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Sure you can. It's really easy.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Pick a new network which will contain the MiCollab box. It can be private, and should be at least a /30 for a single firewall or a /29 for a two-member cluster.&lt;/LI&gt;
&lt;LI&gt;Assign an IP in this network for the firewall. If using a cluster, also assign an IP for each member.&lt;/LI&gt;
&lt;LI&gt;Assign the public IP to the MiCollab box.&lt;/LI&gt;
&lt;LI&gt;Set the MiCollab box's default route to the private IP on the firewall's interface.&lt;/LI&gt;
&lt;LI&gt;Add a 32-bit interface route pointing the public address out the firewall's interface connected to the network with the MiCollab box. The command to add this route will look like this:&lt;/LI&gt;
&lt;/OL&gt;
&lt;LI-CODE lang="markup"&gt;set static-route 1.2.3.4/32 nexthop gateway logical eth1.2345 on&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Due to a complicated set of requirements, I have a firewall which works like this in my environment. It's a bit weird to get used to, but pretty solid.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 13:56:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152437#M25410</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-07-06T13:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Public IP address directly on a server behind Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152438#M25411</link>
      <description>&lt;P&gt;Thanks Bob, I was making an assumption from what was said that routing changes were out of scope or not possible due to the size of the existing external subnet.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 14:04:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152438#M25411</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-06T14:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Public IP address directly on a server behind Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152470#M25414</link>
      <description>&lt;P&gt;Depending on the size of your public IP network, this could be accomplished by breaking it into smaller subnets.&lt;/P&gt;
&lt;P&gt;Create DMZ using one of the small subnets with public IPs and place your Mitel unit in it.&lt;/P&gt;
&lt;P&gt;You will have to configure static routes on the ISP router to forward traffic destined to individual subnets to use Check Point's external IP as the gateway.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2022 02:02:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152470#M25414</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2022-07-07T02:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Public IP address directly on a server behind Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152475#M25416</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/27871"&gt;@Bob_Zimmerman&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;and everyone for tipping the idea.&lt;/P&gt;&lt;P&gt;I now understand how it can be done. It is more complicated that I first thought where it could be just simply a special config in Checkpoint to bridge the traffic directly to Micollab in DMZ.&lt;/P&gt;&lt;P&gt;Will need to involve more parties into the solution.&lt;/P&gt;&lt;P&gt;Much appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jul 2022 03:32:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/152475#M25416</guid>
      <dc:creator>kenn2000</dc:creator>
      <dc:date>2022-07-07T03:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Public IP address directly on a server behind Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/191689#M35357</link>
      <description>&lt;P&gt;Hi Bob,&lt;/P&gt;&lt;P&gt;I'm fairly new with checkpoint, i just have few clarifications with this solution. let me know if my assumptions are correct.&lt;/P&gt;&lt;P&gt;4. I am using a layer 2 switch on the DMZ, would this solution still work&lt;/P&gt;&lt;P&gt;5. Im a bit confused on the command will it be something like this based on the diagram&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;set static-route 1.1.1.2/32 nexthop gateway logical eth.xx (WAN) on&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="cp.png" style="width: 544px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22338i740E559FC239D933/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp.png" alt="cp.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 10:08:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/191689#M35357</guid>
      <dc:creator>blacx_13</dc:creator>
      <dc:date>2023-09-06T10:08:54Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Public IP address directly on a server behind Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/191775#M35390</link>
      <description>&lt;P&gt;4. Yes, you would need to use a switch. Having a router in the path makes things a bit more complicated, but still possible.&lt;/P&gt;
&lt;P&gt;5. You don't have interface names on that diagram, but it would be '&lt;SPAN&gt;set static-route 1.1.1.2/32 nexthop gateway logical &amp;lt;interface leading to the switch labeled DMZ&amp;gt; on'. You would then need to set the default route on 1.1.1.2 to be the cluster VIP on that interface. You &lt;STRONG&gt;should not&lt;/STRONG&gt; use a public IP for that VIP.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 20:59:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/191775#M35390</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-09-06T20:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Public IP address directly on a server behind Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/191835#M35416</link>
      <description>&lt;P&gt;btw, this is not a part of a cluster. so it would be something like this ? since I dont have any VIP&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;'&lt;/SPAN&gt;&lt;SPAN&gt;set static-route 1.1.1.2/32 nexthop gateway eth3 (20.20.20.1 interface) on'&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 02:14:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/191835#M35416</guid>
      <dc:creator>blacx_13</dc:creator>
      <dc:date>2023-09-07T02:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Configure Public IP address directly on a server behind Checkpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/191916#M35433</link>
      <description>&lt;P&gt;&lt;SPAN&gt;set static-route 1.1.1.2/32 nexthop gateway logical eth3 on&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And remember, you need to set the endpoint's default route to the firewall's address on eth3. You may also need to give the endpoint a route to the firewall's address telling it to go out a particular interface. The right way to set all that up depends on the OS on the endpoint.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2023 14:24:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Configure-Public-IP-address-directly-on-a-server-behind/m-p/191916#M35433</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-09-07T14:24:29Z</dc:date>
    </item>
  </channel>
</rss>

