<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ClusterXL with two public IP ranges in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52060#M10316</link>
    <description>Since ClusterXL does not support one interface being in two different subnets, you might have to connect two physical interfaces to that network segment (one for the /24, the other on /30).&lt;BR /&gt;You might need to use private IPs for the interfaces in the /30 segment and make the ClusterXL IP on that interface something in the /30.</description>
    <pubDate>Sun, 28 Apr 2019 16:50:23 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-04-28T16:50:23Z</dc:date>
    <item>
      <title>ClusterXL with two public IP ranges</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52056#M10315</link>
      <description>&lt;P&gt;I can use your advise on this subject.&lt;/P&gt;
&lt;P&gt;Scenario:&lt;/P&gt;
&lt;P&gt;Client getting a /30 and /24 IP ranges from ISP.&lt;/P&gt;
&lt;P&gt;ISP expects connectivity between themselves and a client over /30 network.&lt;/P&gt;
&lt;P&gt;ISP will be forwarding /24 traffic to the single IP in the /30 network.&lt;/P&gt;
&lt;P&gt;ISP does not provide routing equipment.&lt;/P&gt;
&lt;P&gt;Client does not have an L3 device between cluster and ISP.&lt;/P&gt;
&lt;P&gt;What is the appropriate configuration for the cluster and its members to accommodate this scenario?&lt;/P&gt;
&lt;P&gt;I am trying to avoid the use of the manual Proxy ARP and rely on Static NAT for the hosts in DMZs.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="two-public-ranges-draw.io.png" style="width: 891px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1002i079FF493782728C0/image-size/large?v=v2&amp;amp;px=999" role="button" title="two-public-ranges-draw.io.png" alt="two-public-ranges-draw.io.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;Vladimir&lt;/P&gt;</description>
      <pubDate>Sun, 28 Apr 2019 13:54:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52056#M10315</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-04-28T13:54:25Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL with two public IP ranges</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52060#M10316</link>
      <description>Since ClusterXL does not support one interface being in two different subnets, you might have to connect two physical interfaces to that network segment (one for the /24, the other on /30).&lt;BR /&gt;You might need to use private IPs for the interfaces in the /30 segment and make the ClusterXL IP on that interface something in the /30.</description>
      <pubDate>Sun, 28 Apr 2019 16:50:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52060#M10316</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-28T16:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL with two public IP ranges</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52061#M10317</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;Since ClusterXL does not support one interface being in two different subnets, you might have to connect two physical interfaces to that network segment (one for the /24, the other on /30)."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It there a reason for the physical interfaces of the cluster members on these two network to reside on the same L2 segment?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It seems that if they are on a different L2 segment or the same one, the cluster will have to undertake some roundabout internal routing to forward packets between these two networks.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"You might need to use private IPs for the interfaces in the /30 segment and make the ClusterXL IP on that interface something in the /30."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;What about using public IPs from /24 for physical interfaces while using single IP from /30 for external VIP?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Would this permit the inbound and outbound routing for both public ranges? Is so, what additional configuration parameters may be required to differentiate it from common single public VIP when used with RFC 1918 addresses on physical interfaces?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Apr 2019 17:07:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52061#M10317</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-04-28T17:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL with two public IP ranges</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52068#M10319</link>
      <description>&lt;P&gt;Vladimir,&lt;/P&gt;&lt;P&gt;as Dameon wrote, I think the best way is to use two IPs for the physical interfaces outside on it‘s own private network. One of the IPs from your /30 network should be the cluster VIP.&lt;/P&gt;&lt;P&gt;If you need the addresses from the /24 - pool for real hosts you can deploy a new cluster interface for this subnet and attache it to an switch.&lt;/P&gt;&lt;P&gt;If doing only NAT with this pool you can use it in your rulebase. As you wrote, the ISP is routing this network from external to one of the addresses from /30 pool. You don‘t need any proxy ARP for NAT like this.&lt;/P&gt;&lt;P&gt;your question...&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; What about using public IPs from /24 for physical interfaces while using single IP from /30 for external VIP? &amp;lt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I think it‘s better to have the /24 subnet separate from the other IPs, the routing and NAT is clearly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Sun, 28 Apr 2019 18:47:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52068#M10319</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-04-28T18:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL with two public IP ranges</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52069#M10320</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;.&lt;/P&gt;
&lt;P&gt;I was not sure, for some reason, that the cluster will source the outbound traffic from otherwise arbitrary IP addresses from its external interfaces.&lt;/P&gt;
&lt;P&gt;I have just tested it on a single gateway and it does seem to work as you and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;have described:&lt;/P&gt;
&lt;P&gt;Host on internal private network statically NAed to the public IP from the range NOT assigned to any of the interfaces or defined in topology is being routed out with the XLATE of the defined public IP out of its external interface.&lt;/P&gt;
&lt;P&gt;So long as ISP will be forwarding the traffic to /24 in question, this should work for Static NAT purposes.&lt;/P&gt;
&lt;P&gt;The only deviation from norm is that the cluster's portals will be accessible by the IP from /30 range, but the hosts behind it by IPs from /24.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Apr 2019 20:30:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52069#M10320</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-04-28T20:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL with two public IP ranges</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52072#M10323</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;
&lt;P&gt;I'm not 100% sure if I fully understood your question, but there is a way to configure cluster members with different IP ranges:&lt;/P&gt;
&lt;P&gt;See &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk32073&amp;amp;partition=Advanced&amp;amp;product=ClusterXL%22" target="_self"&gt;sk32073&lt;/A&gt; for configuration instructions.&lt;/P&gt;
&lt;P&gt;I configured this last fall for a client who got had only one public IP-address from the ISP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 00:08:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52072#M10323</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2019-04-29T00:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL with two public IP ranges</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52175#M10333</link>
      <description>&lt;P&gt;Vladimir,&lt;/P&gt;&lt;P&gt;you ˋre right.&lt;/P&gt;&lt;P&gt;we had a similar configuration at one of our customer sites. They are using a smaller subnet /29 for internet access and two other /26 subnets for a lot of published webservices and . The /26 are all statically NATed and the IP for remote access ( MobileAccessPortal and VPN) is from /29 subnet.&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 18:34:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52175#M10333</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-04-29T18:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL with two public IP ranges</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52176#M10334</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1967"&gt;@Lari_Luoma&lt;/a&gt;&amp;nbsp;, the question was really in regards to the gateway NATing to the IPs that do not belong to the ranges the interfaces are in.&lt;/P&gt;
&lt;P&gt;I am routinely using it in cases of overlapping VPN domains, but was not sure if it'll work for the normal traffic.&lt;/P&gt;
&lt;P&gt;Looks like it does.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Vladimir&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 18:44:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/52176#M10334</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2019-04-29T18:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL with two public IP ranges</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/184272#M30693</link>
      <description>&lt;P&gt;Hi Lari,&amp;nbsp;&lt;/P&gt;&lt;P&gt;hope you doing well, I have a question same as you mentioned for customer with 1 Public IP, in my case I have 2 Public IP avaliable and other 4 IP's being used 1 for Default Gateway and other 3 for Public Facing services.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried configure Cluster with RFC 1918 FW-1 10.10.10.1/24 and FW-2 10.10.10.2/24 and VIP as Public IP 80.90.239.147/24 (this is dummy Publci IP)&lt;/P&gt;&lt;P&gt;deafult route on both members&lt;/P&gt;&lt;P&gt;set static-route 80.90.239.144/29 nexthop gateway logical eth8 on&lt;/P&gt;&lt;P&gt;set static-route default nexthop gateway address 80.90.239.145 on&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;did set the arp for both private IPs&amp;nbsp; as&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW-1&lt;/P&gt;&lt;P&gt;add arp static ipv4-address 10.10.10.2 macaddress 00:1C:E2:D1:1A:A5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FW-2&lt;/P&gt;&lt;P&gt;add arp static ipv4-address 10.10.10.1 macaddress 00:1C:E1:D2:19:C1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can not route the traffic and internet didnt work&amp;nbsp; good thing was I didnt get any warrning when policy installed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;any sugesstion...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 13:19:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/184272#M30693</guid>
      <dc:creator>kamaladmire1</dc:creator>
      <dc:date>2023-06-19T13:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL with two public IP ranges</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/184313#M30703</link>
      <description>&lt;P&gt;All steps you should need are documented in ClusterXL Admin Guide.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ClusterXL_AdminGuide/Topics-CXLG/Cluster-IP-addresses-on-different-subnets.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ClusterXL_AdminGuide/Topics-CXLG/Cluster-IP-addresses-on-different-subnets.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you still won't get it working, I recommend you open a TAC case for further troubleshooting and debugging.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 02:49:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/184313#M30703</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2023-06-20T02:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL with two public IP ranges</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/184318#M30704</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/86210"&gt;@kamaladmire1&lt;/a&gt;&amp;nbsp;following the given information you have configured different IP subnet for your public IP&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;80.90.239.147/&lt;STRONG&gt;24&lt;/STRONG&gt; your public IP&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;80.90.239.144/&lt;STRONG&gt;29&lt;/STRONG&gt; your default route&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 05:01:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/184318#M30704</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-06-20T05:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: ClusterXL with two public IP ranges</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/184352#M30706</link>
      <description>&lt;P&gt;sorry that was a typo when writing to you it is on&amp;nbsp;&lt;SPAN&gt;80.90.239.147/&lt;/SPAN&gt;&lt;STRONG&gt;29&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 12:47:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ClusterXL-with-two-public-IP-ranges/m-p/184352#M30706</guid>
      <dc:creator>kamaladmire1</dc:creator>
      <dc:date>2023-06-20T12:47:56Z</dc:date>
    </item>
  </channel>
</rss>

