<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Secondary public IP on Wan interface in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-public-IP-on-Wan-interface/m-p/163386#M29203</link>
    <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using ClusterXL configuration with 3600 in R80.40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently our provider is giving us two IPs subnet. The default one is /30 and the second one is /29&lt;/P&gt;&lt;P&gt;I did not find how to add a secondary IP on the Wan interface . Could you please&amp;nbsp; tell me if is it possible to do it directly on the firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or do we need to use a L3 switch between&amp;nbsp; ISP router and Firewall ? Ideally we have to use switch due to the cluster config but want to have L2 only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After that same question if we are using two ISPs , will it be possible to have on both secondary IPs ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
    <pubDate>Mon, 28 Nov 2022 14:38:23 GMT</pubDate>
    <dc:creator>IceCheck</dc:creator>
    <dc:date>2022-11-28T14:38:23Z</dc:date>
    <item>
      <title>Secondary public IP on Wan interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-public-IP-on-Wan-interface/m-p/163386#M29203</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using ClusterXL configuration with 3600 in R80.40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently our provider is giving us two IPs subnet. The default one is /30 and the second one is /29&lt;/P&gt;&lt;P&gt;I did not find how to add a secondary IP on the Wan interface . Could you please&amp;nbsp; tell me if is it possible to do it directly on the firewall?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or do we need to use a L3 switch between&amp;nbsp; ISP router and Firewall ? Ideally we have to use switch due to the cluster config but want to have L2 only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After that same question if we are using two ISPs , will it be possible to have on both secondary IPs ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 28 Nov 2022 14:38:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-public-IP-on-Wan-interface/m-p/163386#M29203</guid>
      <dc:creator>IceCheck</dc:creator>
      <dc:date>2022-11-28T14:38:23Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary public IP on Wan interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-public-IP-on-Wan-interface/m-p/163433#M29204</link>
      <description>&lt;P&gt;You cannot use a secondary IPs/LANs with ClusterXL--this is not supported.&lt;BR /&gt;The correct way to do this is to have your /29 routed to your cluster IP by the ISP router.&lt;BR /&gt;You can either use the /29 for NAT rules OR you can assign it to a physical interface (different from WAN).&lt;BR /&gt;If you're using clustering, assume L3 (Switches) are required on all connected interfaces.&lt;/P&gt;
&lt;P&gt;In the case of sharing the /29 you got from one ISP with another...not possible.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 01:06:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-public-IP-on-Wan-interface/m-p/163433#M29204</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-29T01:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary public IP on Wan interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-public-IP-on-Wan-interface/m-p/163487#M29205</link>
      <description>&lt;P&gt;Thank you for your message and explanation.&lt;/P&gt;&lt;P&gt;Effectively due to clustering we are using Swicthes, ideally L2 but due to this configuration L3.&lt;/P&gt;&lt;P&gt;This feature is not supported for all devices and all version ? Or is it specific to this version and device ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 09:39:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-public-IP-on-Wan-interface/m-p/163487#M29205</guid>
      <dc:creator>IceCheck</dc:creator>
      <dc:date>2022-11-29T09:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary public IP on Wan interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-public-IP-on-Wan-interface/m-p/163489#M29206</link>
      <description>&lt;P&gt;As PhoneBoy said above it's not the recommend way to do it regardless.&lt;/P&gt;
&lt;P&gt;If your ISP cannot route the network towards your Firewalls existing WAN IP (VIP) than you may need to consider dynamic routing to advertise it.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 09:48:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-public-IP-on-Wan-interface/m-p/163489#M29206</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-11-29T09:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary public IP on Wan interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-public-IP-on-Wan-interface/m-p/163563#M29214</link>
      <description>&lt;P&gt;Using multiple IPs on a ClusterXL interface? Not supported on any version.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 14:25:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-public-IP-on-Wan-interface/m-p/163563#M29214</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-29T14:25:18Z</dc:date>
    </item>
    <item>
      <title>Re: Secondary public IP on Wan interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-public-IP-on-Wan-interface/m-p/163578#M29220</link>
      <description>&lt;P&gt;Multiple ISPs should be handled with multiple separate external interfaces. These can be tagged subinterfaces of a physical interface, or they can be multiple physical interfaces. You would then configure ISP Redundancy in the cluster object.&lt;/P&gt;
&lt;P&gt;As for multiple public blocks from one ISP, how is that supposed to work? Are both of these networks on a single broadcast domain?&lt;/P&gt;
&lt;P&gt;If they're both on one broadcast domain and you don't need the firewall itself to initiate new connections out from one of the IPs, you can always just add a proxy ARP statement for it. That will get the traffic from the broadcast domain to the firewall, where you can apply NAT or whatever.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 15:56:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Secondary-public-IP-on-Wan-interface/m-p/163578#M29220</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2022-11-29T15:56:29Z</dc:date>
    </item>
  </channel>
</rss>

