<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Same interface for inbound and outbound internal traffic in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75345#M15284</link>
    <description>&lt;P&gt;Thanks for you comment &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17364"&gt;@Maarten_Sjouw&lt;/a&gt; !&lt;/P&gt;&lt;P&gt;I will desist. The common sentence in teh comments of all of you is "This is a bad idead".&lt;/P&gt;&lt;P&gt;Anyways I will test the scenario in a lab and let you know.&lt;/P&gt;&lt;P&gt;Thanks guys!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS:&lt;/P&gt;&lt;P&gt;Redirecting the traffic is very easy.&lt;/P&gt;&lt;P&gt;A Policy based route overrides the general routing table, setting the "default-nexthop" the firewall.&lt;/P&gt;&lt;P&gt;I have tested this step already without issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lanello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Feb 2020 21:51:35 GMT</pubDate>
    <dc:creator>lcarrau</dc:creator>
    <dc:date>2020-02-14T21:51:35Z</dc:date>
    <item>
      <title>Same interface for inbound and outbound internal traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75287#M15267</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to perform Access Control and Threat Prevention between the local networks.&lt;/P&gt;&lt;P&gt;Description:&lt;/P&gt;&lt;P&gt;All networks are connected to a Router, which will detour all traffic to the Security Gateway, even when the destination is direct attached. For the Security Gateway, the inbound and outbound interface is the same in all packets but there is no assymetrical routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;Will the Threat Prevention and Firewall Blades work without issues on this scenario/layout?&lt;/P&gt;&lt;P&gt;Will the SG send to the router a ICMP Redirect Message?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lanello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 14:26:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75287#M15267</guid>
      <dc:creator>LCarrau808</dc:creator>
      <dc:date>2020-02-14T14:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Same interface for inbound and outbound internal traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75288#M15268</link>
      <description>&lt;P&gt;Not a good idea. Use Bridge mode instead or IP forwarding in a normal mode.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 14:30:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75288#M15268</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-02-14T14:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Same interface for inbound and outbound internal traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75300#M15273</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;For the Bridge Mode can get a little bit complicated.&lt;/P&gt;&lt;P&gt;The Checkpoint would be at a side instead Man-In-The-Middle (Check the drawing).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Layout.png" style="width: 437px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/4457i884D2B16D5ADDBE7/image-dimensions/437x547?v=v2" width="437" height="547" role="button" title="Layout.png" alt="Layout.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;It is a ClusterXL with 6 VSX. Two of them are Perimeter Firewalls, but I want to perform IPS between the local networks.&lt;/P&gt;&lt;P&gt;I know I can connect the networks direct to the Checkpoint and get rid of the router, but I still want to have it arround.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lanello&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 15:29:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75300#M15273</guid>
      <dc:creator>LCarrau808</dc:creator>
      <dc:date>2020-02-14T15:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: Same interface for inbound and outbound internal traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75301#M15274</link>
      <description>&lt;P&gt;Hi, as stated before.. not a good idea. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its like a firewall-on-a-stick setup, and I would guess that you will need to spend some time to get the routing set up and working. But yeah - sure I can't see that it wont work.&lt;/P&gt;&lt;P&gt;I have had setups where you had a main vrf with several 'child' vrf's, connecting the firewall to the main vrf and providing access between the 'childs' on the SG. This can be comapred to what you are asking.&lt;/P&gt;&lt;P&gt;Regaring the question on 'icmp redirects' vs. 'all networks connected to a router' gives me a confused picture on how you are planning to actually set this up.. is there to be several networks/subnets ? If you have ex. 2 client subnets and a subnet where the SG is to be placed, the packet flow will be pretty regular, just entering and leaving on same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But all in all. not a good idea.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 15:30:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75301#M15274</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2020-02-14T15:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: Same interface for inbound and outbound internal traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75302#M15275</link>
      <description>&lt;P&gt;Your example with the VRF is exaclty the same I want to do.&lt;/P&gt;&lt;P&gt;The routing part is already solved with a forced unconditional next-hop leading the packets to the firewall and the default route for the SG is the Core Router again (that's the plan).&lt;/P&gt;&lt;P&gt;Yes, there is a separated subnet for the comm between the SG and the Router.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the VRF scenario is working for you, I can see the light at the end of the tunnel.&lt;/P&gt;&lt;P&gt;But you still say it is not a good idea...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have you inter-VRF traffic that pass through the SG?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 15:41:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75302#M15275</guid>
      <dc:creator>LCarrau808</dc:creator>
      <dc:date>2020-02-14T15:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Same interface for inbound and outbound internal traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75303#M15276</link>
      <description>Hi, ok - well. It depends on your design. For me the main thing was to have seperation between the vrf's, but do to 'stuff' I had to allow some traffic to pass between them, and thus getting the setup I was refering to. Worked fine..&lt;BR /&gt;&lt;BR /&gt;It pretty much comes down to the network design. For me it added a bit of extra management, just to get people to understand the design. And troubleshooting got a bit more tedious.. NAT would probably be a bit 'interesting'.. Voice, qos, as an example, I have no idea. You have to take into consideration how you build policy set..working with zones etc..&lt;BR /&gt;&lt;BR /&gt;But in general, "basic firewall functionality was fine.</description>
      <pubDate>Fri, 14 Feb 2020 15:51:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75303#M15276</guid>
      <dc:creator>vinceneil666</dc:creator>
      <dc:date>2020-02-14T15:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: Same interface for inbound and outbound internal traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75324#M15280</link>
      <description>In your configuration all traffic between VLANs can be easily routed trhough the FW's when you use the FWs as their default gateways.&lt;BR /&gt;Traffic between device in the same LAN will never work as both devices will always directly address the other device in the same LAN. Redirecting this to the FW is not only a bad idea but also very hard to do.&lt;BR /&gt;</description>
      <pubDate>Fri, 14 Feb 2020 18:16:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75324#M15280</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-02-14T18:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: Same interface for inbound and outbound internal traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75345#M15284</link>
      <description>&lt;P&gt;Thanks for you comment &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17364"&gt;@Maarten_Sjouw&lt;/a&gt; !&lt;/P&gt;&lt;P&gt;I will desist. The common sentence in teh comments of all of you is "This is a bad idead".&lt;/P&gt;&lt;P&gt;Anyways I will test the scenario in a lab and let you know.&lt;/P&gt;&lt;P&gt;Thanks guys!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS:&lt;/P&gt;&lt;P&gt;Redirecting the traffic is very easy.&lt;/P&gt;&lt;P&gt;A Policy based route overrides the general routing table, setting the "default-nexthop" the firewall.&lt;/P&gt;&lt;P&gt;I have tested this step already without issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Lanello&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2020 21:51:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75345#M15284</guid>
      <dc:creator>lcarrau</dc:creator>
      <dc:date>2020-02-14T21:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: Same interface for inbound and outbound internal traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75363#M15286</link>
      <description>I'm sorry for that typo..&lt;BR /&gt;Are all systems in that VLAn capable of setting that policy route?&lt;BR /&gt;Only other method I can think of is by setting the IP to a /32 and set the default gateway, but normally those types of config are not accepted by most OS's.</description>
      <pubDate>Sat, 15 Feb 2020 09:51:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75363#M15286</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-02-15T09:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Same interface for inbound and outbound internal traffic</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75364#M15287</link>
      <description>&lt;P&gt;I don't need to inspect traffic between the hosts on the same network.&lt;/P&gt;&lt;P&gt;Only the inter-subnet traffic.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Feb 2020 11:53:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Same-interface-for-inbound-and-outbound-internal-traffic/m-p/75364#M15287</guid>
      <dc:creator>lcarrau</dc:creator>
      <dc:date>2020-02-15T11:53:01Z</dc:date>
    </item>
  </channel>
</rss>

