<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about vpn/ipsec on external interface with private addresses in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/87287#M17529</link>
    <description>&lt;P&gt;Thank you &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt; , it make sense&lt;/P&gt;&lt;P&gt;What do you mean with a dummy cluster interface? a unused VLAN interface for example?&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Jun 2020 10:16:15 GMT</pubDate>
    <dc:creator>elapuente</dc:creator>
    <dc:date>2020-06-04T10:16:15Z</dc:date>
    <item>
      <title>Question about vpn/ipsec on external interface with private addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/87197#M17502</link>
      <description>&lt;P&gt;Hello everyone!!!&lt;/P&gt;&lt;P&gt;We ask for the community help for solving the following configuration.&lt;/P&gt;&lt;P&gt;First of all, we have an ISP cluster of routers and a Checkpoint cluster. It's a very simple configuration. There is a /29 public IPs that the ISP routes to checkpoint.&lt;/P&gt;&lt;P&gt;ISP routers and Checkpoint are connected via a routing network, with private address (10.100.250.0/24).&lt;/P&gt;&lt;P&gt;So, 10.100.250.1,2,3 are the IPs on routers side, and 10.100.250.252,253,254 are the checkpoint cluster addresses. The ISP routes the public range to ip 10.100.250.254 (checkpoint virtual ip).&lt;/P&gt;&lt;P&gt;There is no public address on the checkpoint cluster. We have some services published with some NAT rules.&lt;/P&gt;&lt;P&gt;But, we want to enable the Mobile portal, and be able to create site-to-site IPSec tunnel.&lt;/P&gt;&lt;P&gt;The problem we have is that we cannot make "https://&amp;lt;publicip&amp;gt;/sslvpn" URL work, because there is no public ip on the Checkpoint. We cannot make NAT 1-to-1 for the firewall itself. We tried with Proxy ARP, with no success. It worked with an interface alias on one of the checkpoint, but it's not supported with ClusterXL (and cannot add another virtual ip on the external interface).&lt;/P&gt;&lt;P&gt;There is two possible solutions (changing interconnect network):&lt;/P&gt;&lt;P&gt;- 3 public ips on checkpoint cluster external interfaces and 3 public ips on router cluster&lt;/P&gt;&lt;P&gt;- 1 public ips on checkpoint cluster external interfaces and 3 public ips on router cluster (sk32073)&lt;/P&gt;&lt;P&gt;But we only have 6 public IPs, and don't want to wasted on the routing network.&lt;/P&gt;&lt;P&gt;is there anyone with a similar configuration?&lt;/P&gt;&lt;P&gt;Thank you in advance for the help!!&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 15:29:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/87197#M17502</guid>
      <dc:creator>elapuente</dc:creator>
      <dc:date>2020-06-03T15:29:24Z</dc:date>
    </item>
    <item>
      <title>Re: Question about vpn/ipsec on external interface with private addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/87205#M17504</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/44785"&gt;@elapuente&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;add a new dummy clusterinterface.&lt;BR /&gt;You can use private IPs for the cluster members IP addresses and use one of the public IPs with /32 as virtual cluster IP. You don't need to add any routes. No traffic will be leaving this interface, but the local services are listen on this IP.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Wolfgang&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 17:51:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/87205#M17504</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-06-03T17:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: Question about vpn/ipsec on external interface with private addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/87287#M17529</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt; , it make sense&lt;/P&gt;&lt;P&gt;What do you mean with a dummy cluster interface? a unused VLAN interface for example?&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 10:16:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/87287#M17529</guid>
      <dc:creator>elapuente</dc:creator>
      <dc:date>2020-06-04T10:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Question about vpn/ipsec on external interface with private addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/87296#M17535</link>
      <description>&lt;P&gt;Yes&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/44785"&gt;@elapuente&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;we did this with a new VLAN interface. There is no need to use&amp;nbsp; a physical interface.&lt;/P&gt;
&lt;P&gt;You need an interface defined on the cluster with one of the public IPs.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jun 2020 10:45:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/87296#M17535</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-06-04T10:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Question about vpn/ipsec on external interface with private addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/122164#M22640</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Wolfgang,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;We have a similar setup. but doesn't have VLAN interface on firewall external interface. So can we define Public IP on Cluster IP and Gateway nodes remain as "none". Will that work?&lt;/P&gt;&lt;P&gt;-&amp;gt; CP External Int connected to Internet Router&lt;/P&gt;&lt;P&gt;-&amp;gt; But we don't have any VLAN interface on CP External Int firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;VPN Gateway -------&amp;gt;&amp;nbsp; Internet-----&amp;gt; Internet Router -----&amp;gt; Checkpoint FW / VPN&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 10:51:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/122164#M22640</guid>
      <dc:creator>AnujPratap</dc:creator>
      <dc:date>2021-06-25T10:51:37Z</dc:date>
    </item>
    <item>
      <title>Re: Question about vpn/ipsec on external interface with private addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/122170#M22642</link>
      <description>&lt;P&gt;Yes, it's possible to set private IPs for your clusternodes in the same subnet and the virtual cluster IP defined as public IP. But with this setup it's not possible to manage your cluster from the external site.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 12:25:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/122170#M22642</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-06-25T12:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Question about vpn/ipsec on external interface with private addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/122188#M22645</link>
      <description>&lt;P&gt;Thanks Wolfgang for your prompt response.&lt;/P&gt;&lt;P&gt;One more query, if you don't mind.&lt;/P&gt;&lt;P&gt;Do we need to do physical cabling with Clusternodes interfaces?&lt;BR /&gt;or&lt;BR /&gt;we can just configure them with the Private IP and Public IP on Cluster-VIP.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 15:01:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/122188#M22645</guid>
      <dc:creator>AnujPratap</dc:creator>
      <dc:date>2021-06-25T15:01:26Z</dc:date>
    </item>
    <item>
      <title>Re: Question about vpn/ipsec on external interface with private addresses</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/122224#M22650</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/29732"&gt;@AnujPratap&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I‘m not sure understanding your question.&lt;/P&gt;
&lt;P&gt;You have to connect the physical interfaces on both nodes via a switch or direct cable to get in up state and get your cluster VIP up.&lt;/P&gt;
&lt;P&gt;Was this your question ore something different?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 19:50:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-vpn-ipsec-on-external-interface-with-private/m-p/122224#M22650</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-06-25T19:50:00Z</dc:date>
    </item>
  </channel>
</rss>

