<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cluster configuration with single public IP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-configuration-with-single-public-IP/m-p/179423#M32875</link>
    <description>&lt;P&gt;When sending traffic through a router in a different IP network than the cluster members' real addresses, you need two routes on each member. One to tell the members how to get to the gateway, and one to tell them to go through the gateway to get somewhere else. For example:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;set static-route 10.20.30.40/32 nexthop gateway logical eth1 on
set static-route default nexthop gateway address 10.20.30.40 on&lt;/LI-CODE&gt;</description>
    <pubDate>Fri, 28 Apr 2023 14:02:38 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2023-04-28T14:02:38Z</dc:date>
    <item>
      <title>Cluster configuration with single public IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-configuration-with-single-public-IP/m-p/179422#M32874</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a problem configuring a second internet link.&lt;/P&gt;&lt;P&gt;On that link I have only one public IP, but I have a cluster of two appliances.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I put IP addresses on both members: 192.168.79.1 and 192.168.79.2. And VIP I set as a public ip address.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But when I try to set static route to gw IP- traffic is sent through wrong (main) interface,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;In Administration guide I read, that&amp;nbsp; I need to mark "local scope". But if&amp;nbsp;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;I do that- then I can't add IP as a gateway, but only interface. At that moment CP start sending packet trough correct interface, but still "time out".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Problem is- I don't know how to route specific traffic to second gw.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Maybe I'm missing something?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Apr 2023 13:49:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-configuration-with-single-public-IP/m-p/179422#M32874</guid>
      <dc:creator>Strongiukas</dc:creator>
      <dc:date>2023-04-28T13:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster configuration with single public IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-configuration-with-single-public-IP/m-p/179423#M32875</link>
      <description>&lt;P&gt;When sending traffic through a router in a different IP network than the cluster members' real addresses, you need two routes on each member. One to tell the members how to get to the gateway, and one to tell them to go through the gateway to get somewhere else. For example:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;set static-route 10.20.30.40/32 nexthop gateway logical eth1 on
set static-route default nexthop gateway address 10.20.30.40 on&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 28 Apr 2023 14:02:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Cluster-configuration-with-single-public-IP/m-p/179423#M32875</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-04-28T14:02:38Z</dc:date>
    </item>
  </channel>
</rss>

