<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enabling Anti-Phishing on R81.20 VSX without Internet interface in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Enabling-Anti-Phishing-on-R81-20-VSX-without-Internet-interface/m-p/190499#M54565</link>
    <description>&lt;P&gt;That's very correct, I used this method in the past for so-called loopbacks. The issue here is that&amp;nbsp; dummy public IP is required. Since it will be up if either connected with a port or bond VLAN, it will be redistributed in dynamic routing and will then require specific routemaps where we used a generic redistribute to announce connected networks. Also, I understand in the case of multiple VS we'll need on top of that to configure a dummy public IP and FQDN for each one. Not sure the customers will find this elegant.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Aug 2023 16:24:04 GMT</pubDate>
    <dc:creator>Alex-</dc:creator>
    <dc:date>2023-08-24T16:24:04Z</dc:date>
    <item>
      <title>Enabling Anti-Phishing on R81.20 VSX without Internet interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Enabling-Anti-Phishing-on-R81-20-VSX-without-Internet-interface/m-p/190450#M54562</link>
      <description>&lt;P&gt;VSX R81.20 T24&lt;/P&gt;&lt;P&gt;I'm looking for the best way to et-up Anti-Phishing on VS's doing HTTPS Inspection but don't have a public interface, this is done by an upstream system.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk178769" target="_blank" rel="noopener"&gt;Zero Phishing In-Browser protection is not working for HTTP sites (checkpoint.com)&lt;/A&gt;&amp;nbsp;mentions that it's best practice to use a public IP for the FQDN, even if it's a dummy one and assign it to a disconnected interface.&lt;/P&gt;&lt;P&gt;Now the issue with VSX is that assigning an IP to a discrete disconnected interface will cause this IP to be monitored and the VS will go from Active/Standby to Active/Down.&lt;/P&gt;&lt;P&gt;Is it then recommended to still enable the interface and create a connectivity between the VSX cluster members for that IP.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 08:56:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Enabling-Anti-Phishing-on-R81-20-VSX-without-Internet-interface/m-p/190450#M54562</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-08-24T08:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling Anti-Phishing on R81.20 VSX without Internet interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Enabling-Anti-Phishing-on-R81-20-VSX-without-Internet-interface/m-p/190458#M54563</link>
      <description>&lt;P&gt;I would strongly suggest to contact TAC !&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 10:33:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Enabling-Anti-Phishing-on-R81-20-VSX-without-Internet-interface/m-p/190458#M54563</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-08-24T10:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling Anti-Phishing on R81.20 VSX without Internet interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Enabling-Anti-Phishing-on-R81-20-VSX-without-Internet-interface/m-p/190469#M54564</link>
      <description>&lt;P&gt;We had a similar use case in the past, need of a dummy interface. We&amp;nbsp; solved this with a new VLAN interface on an existing BOND. To get the interface up you have to configure the connected switchports with the same VLAN-ID, because they are monitored as you wrote. Normally only first and last VLAN on a trunk are monitored, you could use one in between without to be monitored . But for troubleshooting and some other interaction it's better to configure this like a normal, including the switch.&lt;/P&gt;
&lt;P&gt;If you can't use a VLAN you can use a new physical interface but you have to connect these to a switch to get the link up or if only two gateways are used via a direct attached cable.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 12:44:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Enabling-Anti-Phishing-on-R81-20-VSX-without-Internet-interface/m-p/190469#M54564</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-08-24T12:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling Anti-Phishing on R81.20 VSX without Internet interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Enabling-Anti-Phishing-on-R81-20-VSX-without-Internet-interface/m-p/190499#M54565</link>
      <description>&lt;P&gt;That's very correct, I used this method in the past for so-called loopbacks. The issue here is that&amp;nbsp; dummy public IP is required. Since it will be up if either connected with a port or bond VLAN, it will be redistributed in dynamic routing and will then require specific routemaps where we used a generic redistribute to announce connected networks. Also, I understand in the case of multiple VS we'll need on top of that to configure a dummy public IP and FQDN for each one. Not sure the customers will find this elegant.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 16:24:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Enabling-Anti-Phishing-on-R81-20-VSX-without-Internet-interface/m-p/190499#M54565</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2023-08-24T16:24:04Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling Anti-Phishing on R81.20 VSX without Internet interface</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Enabling-Anti-Phishing-on-R81-20-VSX-without-Internet-interface/m-p/190505#M54566</link>
      <description>&lt;P&gt;I don‘t know your specific requirements. But as an idea….. you can create a new virtual firewall with the dummy public IP and a very simple policy (your AntiPhishing). Your outgoing traffic can be routed through these new system from the other VSs ?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Aug 2023 18:43:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Enabling-Anti-Phishing-on-R81-20-VSX-without-Internet-interface/m-p/190505#M54566</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-08-24T18:43:29Z</dc:date>
    </item>
  </channel>
</rss>

