<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bridge mode with security gateway 3100 - Possible? in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Bridge-mode-with-security-gateway-3100-Possible/m-p/64867#M1651</link>
    <description>There is one other option if you need the extra interfaces, just split your network into smaller chunks and setup DHCP on each separate network assigned to the different interfaces. Add a rule to allow these networks full access to each other and you are good to go.</description>
    <pubDate>Sat, 12 Oct 2019 07:25:33 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2019-10-12T07:25:33Z</dc:date>
    <item>
      <title>Bridge mode with security gateway 3100 - Possible?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Bridge-mode-with-security-gateway-3100-Possible/m-p/64807#M1646</link>
      <description>&lt;P&gt;Dear community,&lt;/P&gt;&lt;P&gt;I'm installing a new security appliance 3100 on one site of my company, that has 5 ports (eth1, ..., eth5).&lt;/P&gt;&lt;P&gt;eth1 is connected to WAN with a public IP address&lt;/P&gt;&lt;P&gt;eth2 is connected to LAN with a private IP address 192.168.33.254/24 and a DHCP server for LAN clients.&lt;/P&gt;&lt;P&gt;192.168.33.0/24 is part of a VPN domain. Everything works well with this configuration.&lt;/P&gt;&lt;P&gt;Now, as it's a very small site, I'd like to use eth3, eth4 &amp;amp; eth5 for my LAN network too, so I would not need to use an additional switch. I created a bridge called "br1" with IP address 192.168.33.254 and added eth2 &amp;amp; eth3 as members.&lt;/P&gt;&lt;P&gt;Since, I'm not able to do anything from eth2 or eth3. I can't get an IP address, I can't reach Internet (even with a static IP address). The SmartCenter logs have entry for dropped packets with reason "Missing OS route".&lt;/P&gt;&lt;P&gt;My questions are:&lt;/P&gt;&lt;P&gt;- Is this design really supported?&lt;/P&gt;&lt;P&gt;- Do you have any idea about what could prevent this design from working?&lt;/P&gt;&lt;P&gt;Thank you in advance for your suggestions.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 09:49:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Bridge-mode-with-security-gateway-3100-Possible/m-p/64807#M1646</guid>
      <dc:creator>nicolas1984</dc:creator>
      <dc:date>2019-10-11T09:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Bridge mode with security gateway 3100 - Possible?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Bridge-mode-with-security-gateway-3100-Possible/m-p/64832#M1648</link>
      <description>To be honest I would just buy a 5 port switch for 30 bucks and be done with it, spending more time on it is just not worth the effort.&lt;BR /&gt;I agree that it should work but it sounds like this is more a site that should be using a 14x0 instead, the LAN ports there can be setup as a switch, but indeed it is embedded, not full blown Gaia and when you need it...</description>
      <pubDate>Fri, 11 Oct 2019 17:33:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Bridge-mode-with-security-gateway-3100-Possible/m-p/64832#M1648</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-10-11T17:33:29Z</dc:date>
    </item>
    <item>
      <title>Re: Bridge mode with security gateway 3100 - Possible?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Bridge-mode-with-security-gateway-3100-Possible/m-p/64846#M1649</link>
      <description>&lt;P&gt;nicolas1984,&lt;/P&gt;&lt;P&gt;I think this can‘t work. If you put two interfaces in &amp;nbsp;bridge mode, the work as a normal bridge like a hardware bridge from the last century. You had then a small switch or better hub with two interfaces. Packets coming from one site of the bridge are forwarded to the other and vice versa. No routing is done, which you need if you want to go out to the internet.&lt;/P&gt;&lt;P&gt;Use a small switch and you‘ll be happy, or Martens idea for a 14xx appliance with LAN-Ports working as switch.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 21:23:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Bridge-mode-with-security-gateway-3100-Possible/m-p/64846#M1649</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-10-11T21:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: Bridge mode with security gateway 3100 - Possible?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Bridge-mode-with-security-gateway-3100-Possible/m-p/64847#M1650</link>
      <description>You can only put two interfaces in a bridge.&lt;BR /&gt;More than that are not supported.</description>
      <pubDate>Fri, 11 Oct 2019 21:50:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Bridge-mode-with-security-gateway-3100-Possible/m-p/64847#M1650</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-11T21:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: Bridge mode with security gateway 3100 - Possible?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Bridge-mode-with-security-gateway-3100-Possible/m-p/64867#M1651</link>
      <description>There is one other option if you need the extra interfaces, just split your network into smaller chunks and setup DHCP on each separate network assigned to the different interfaces. Add a rule to allow these networks full access to each other and you are good to go.</description>
      <pubDate>Sat, 12 Oct 2019 07:25:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Bridge-mode-with-security-gateway-3100-Possible/m-p/64867#M1651</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-10-12T07:25:33Z</dc:date>
    </item>
  </channel>
</rss>

