<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bridge Mode VS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79235#M9501</link>
    <description>I really can't tell you as I have never needed this nor tested it. But you could try it yourself, however I think you really do need to add the VLAN subinterface for those VLANs you want to allow through.</description>
    <pubDate>Sun, 22 Mar 2020 18:07:00 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2020-03-22T18:07:00Z</dc:date>
    <item>
      <title>Bridge Mode VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/78752#M9494</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I am struggling to configure bridge mode in my VS with active/standby clusterXL. In my understanding, if you are running bridge mode, you need to have bridge interface however, when I tried to create a new VS, it asked me to tag the VLAN and asked what is the external and internal interfaces.&lt;/P&gt;&lt;P&gt;So I created a bridge interfaces beforehand I enabled the VSX feature and created the bridge ID in the smart console as shown below,&lt;/P&gt;&lt;P&gt;br1 = eth1 and eth2&lt;/P&gt;&lt;P&gt;br2 = eth3 and eth4&lt;/P&gt;&lt;P&gt;In the smart console, I created a new VS and associate br1.x (x = VLAN ID). Is this the correct way to configure the bridge mode in VSX? Also, how can you determine the external and internal if you only have now br interface?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 05:16:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/78752#M9494</guid>
      <dc:creator>CyberBreaker</dc:creator>
      <dc:date>2020-03-19T05:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: Bridge Mode VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79167#M9495</link>
      <description>That sounds correct.&lt;BR /&gt;In general you should mark Bridge interfaces as External.</description>
      <pubDate>Sun, 22 Mar 2020 00:21:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79167#M9495</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-22T00:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Bridge Mode VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79188#M9496</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;so I created the "br1" and "br2" in GAIA however, when I configure the VS in SmartConsole, it ask me for a VLAN. Do I need to put the VLAN per "br" interface? For example, br1.20 then br1.30?&lt;/P&gt;&lt;P&gt;Another way that I tried it to setup everything in Smart Console which includes the VS in bridge mode then I configured the following interfaces,&lt;/P&gt;&lt;P&gt;eth1.X and eth2.X&lt;/P&gt;&lt;P&gt;eth1.Y and eth2.Y&lt;/P&gt;&lt;P&gt;eth1.Z and eth2.Z&lt;/P&gt;&lt;P&gt;Then, Smart Conole successfully pushed down the config and policy to the VS then when I checked the CLI of the gateway, it created automatically the bridge interfaces.&lt;/P&gt;&lt;P&gt;Is this correct also?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 22 Mar 2020 06:21:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79188#M9496</guid>
      <dc:creator>CyberBreaker</dc:creator>
      <dc:date>2020-03-22T06:21:23Z</dc:date>
    </item>
    <item>
      <title>Re: Bridge Mode VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79189#M9497</link>
      <description>I believe both of those approaches will work.&lt;BR /&gt;However, I will have to defer to someone with a little more recent VSX experience than me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Sun, 22 Mar 2020 06:25:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79189#M9497</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-22T06:25:55Z</dc:date>
    </item>
    <item>
      <title>Re: Bridge Mode VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79190#M9498</link>
      <description>&lt;P&gt;Thank you so much&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;, it is such a bit tricky to configure VS in bridge mode compare to a non-VS gateway.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Mar 2020 06:28:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79190#M9498</guid>
      <dc:creator>CyberBreaker</dc:creator>
      <dc:date>2020-03-22T06:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: Bridge Mode VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79201#M9499</link>
      <description>When you add the BR1 and BR2 interfaces to your VSX gateway, and you do not want to use VLAN's on thoes interfaces, you should not tick the Trunk box in that list. So when it is asking for VLAN information the interface has been set to trunk in topology, just untick that and you should not get the VLAN request.</description>
      <pubDate>Sun, 22 Mar 2020 07:45:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79201#M9499</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-22T07:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Bridge Mode VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79202#M9500</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17364"&gt;@Maarten_Sjouw&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thanks for the feedback. But if I did not tick the TRUNK box, does it means that the bridge interfaces will not act as a trunk? My target is to make my bridge interfaces as trunk so that whatever VLANs configured in the switches, it can pass through the VS.&lt;/P&gt;&lt;P&gt;Also, the other way that I tried is to configure my VS as bridge mode then I configured in Smart Console the eth1.X and eth2.X then eth1.Y and eth2.Y. The when I checked the CLI, it automatically configured bridge interfaces.&lt;/P&gt;&lt;P&gt;Thank you so much.&lt;/P&gt;</description>
      <pubDate>Sun, 22 Mar 2020 07:57:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79202#M9500</guid>
      <dc:creator>CyberBreaker</dc:creator>
      <dc:date>2020-03-22T07:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Bridge Mode VS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79235#M9501</link>
      <description>I really can't tell you as I have never needed this nor tested it. But you could try it yourself, however I think you really do need to add the VLAN subinterface for those VLANs you want to allow through.</description>
      <pubDate>Sun, 22 Mar 2020 18:07:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Bridge-Mode-VS/m-p/79235#M9501</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-03-22T18:07:00Z</dc:date>
    </item>
  </channel>
</rss>

