<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SIC and Policy installation in remote checkpoint gateway R80.40 in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129581#M23617</link>
    <description>&lt;P&gt;Until the gateway has a real policy, IP routing is disabled at the OS level.&lt;BR /&gt;I’m guessing that’s why you’re getting ICMP Unreachable in this situation.&lt;BR /&gt;That said the gateway is fully aware of all the interfaces it has, so doesn’t need a route from one interface to another.&lt;/P&gt;
&lt;P&gt;Regardless, the initial/default policy should allow the necessary traffic.&lt;BR /&gt;There is no way to configure the policy locally by design.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Sep 2021 14:30:42 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-09-16T14:30:42Z</dc:date>
    <item>
      <title>SIC and Policy installation in remote checkpoint gateway R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129555#M23615</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;I am working on a setup where local mgmt server has to configure and manage remote checkpoint gateway that is in different network via internet &amp;amp; one of SD-WAN service chain.&lt;/P&gt;&lt;P&gt;Below is the flow:&lt;/P&gt;&lt;P&gt;CP- SMS &amp;gt; local CP &amp;gt; Local SD-WAN &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;IPSEC/Tunnel &amp;gt;&amp;gt;&amp;gt;&amp;gt; Remote SD-WAN &amp;gt; eth6 - Remote CP - eth7&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using eth6 for service chain from which remote CP gets traffic and eth7 for mgmt interface&lt;/P&gt;&lt;P&gt;traceroute from remote CP to local CP-SMS works but reverse fails at remote CP eth6 interface as it drops the traffic&lt;/P&gt;&lt;P&gt;13:02:51.046622 IP 10.91.117.14.48954 &amp;gt; UCPE32-CP.33471: UDP, length 40&lt;BR /&gt;13:02:51.046644 IP 10.91.117.14.21790 &amp;gt; UCPE32-CP.33476: UDP, length 40&lt;BR /&gt;13:02:51.046657 IP 10.91.117.14.64158 &amp;gt; UCPE32-CP.33475: UDP, length 40&lt;BR /&gt;13:02:51.046680 IP UCPE32-CP &amp;gt; 10.91.117.14: ICMP UCPE32-CP udp port 33472 unreachable, length 76&lt;BR /&gt;13:02:51.046730 IP 10.91.117.14.43784 &amp;gt; UCPE32-CP.33478: UDP, length 40&lt;BR /&gt;13:02:51.046792 IP UCPE32-CP &amp;gt; 10.91.117.14: ICMP UCPE32-CP udp port 33473 unreachable, length 76&lt;BR /&gt;13:02:51.046842 IP UCPE32-CP &amp;gt; 10.91.117.14: ICMP UCPE32-CP udp port 33468 unreachable, length 76&lt;/P&gt;&lt;P&gt;I have few questions:&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. As remote checkpoint is newly installed and to initially configure it we need to have a connectivity to mgmt server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;with the current status, will it allow traffic to flow from eth6 &amp;gt;&amp;gt; eth7 internally? in my case its dropping and if yes, in what condition?&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. How in production the checkpoint gateways are configured with a central SMS on SIC &amp;amp; policy installation? should we make the route directly to eth7 of remote checkpoint gateway from mgmt server ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. I have done fw unloadlocal and will this still deny traffic to flow inside checkpoint?&amp;nbsp;&lt;/P&gt;&lt;P&gt;4. As there is default policy which deny traffic from external network, is there any way , I can locally install the policy in checkpoint gateway ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate your response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Rajnish&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 08:45:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129555#M23615</guid>
      <dc:creator>RajnishR</dc:creator>
      <dc:date>2021-09-16T08:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: SIC and Policy installation in remote checkpoint gateway R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129560#M23616</link>
      <description>&lt;P&gt;Additional to that,&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is stopping eth7 to get traffic from eth6 in checkpoint. I mean when I try to ping/traceroute/ssh eth7 IP, it does not reach eth7 but stays at eth6 only&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 09:04:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129560#M23616</guid>
      <dc:creator>RajnishR</dc:creator>
      <dc:date>2021-09-16T09:04:52Z</dc:date>
    </item>
    <item>
      <title>Re: SIC and Policy installation in remote checkpoint gateway R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129581#M23617</link>
      <description>&lt;P&gt;Until the gateway has a real policy, IP routing is disabled at the OS level.&lt;BR /&gt;I’m guessing that’s why you’re getting ICMP Unreachable in this situation.&lt;BR /&gt;That said the gateway is fully aware of all the interfaces it has, so doesn’t need a route from one interface to another.&lt;/P&gt;
&lt;P&gt;Regardless, the initial/default policy should allow the necessary traffic.&lt;BR /&gt;There is no way to configure the policy locally by design.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 14:30:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129581#M23617</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-16T14:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: SIC and Policy installation in remote checkpoint gateway R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129644#M23622</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;It worked when I unloaded the default policy and then did the SIC and policy installation from mgmt server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;But as I am trying to access from MGMT server to Remote gateway, I can only route it from local checkpoint mgmt interface but not from the LAN interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I use checkpoint LAN interface to forward traffic to remote gateway?&lt;/P&gt;&lt;P&gt;This flow works:&amp;nbsp;&lt;/P&gt;&lt;P&gt;MGMT Server &amp;gt;&amp;gt;&amp;gt;&amp;gt; MGMT Interface Checkpoint &amp;gt;&amp;gt;&amp;gt; External Interface Checkpoint &amp;gt;&amp;gt;&amp;gt; Internet &amp;gt;&amp;gt; Remote Checkpoint gateway&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But this does not work:&amp;nbsp;&lt;/P&gt;&lt;P&gt;MGMT Server &amp;gt;&amp;gt;&amp;gt;&amp;gt; LAN Interface Checkpoint &amp;gt; XXXXXX&amp;gt;&amp;gt; External Interface Checkpoint &amp;gt;&amp;gt;&amp;gt; Internet &amp;gt;&amp;gt; Remote Checkpoint gateway&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have allowed all kind of traffic but the mgmt traffic coming on LAN interface is dropped and not forwarded to external interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me to solve it.&lt;/P&gt;&lt;P&gt;Thanks, Rajnish&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 11:32:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129644#M23622</guid>
      <dc:creator>RajnishR</dc:creator>
      <dc:date>2021-09-17T11:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: SIC and Policy installation in remote checkpoint gateway R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129647#M23623</link>
      <description>&lt;P&gt;I can only speak from my own experience, but whenever I saw issue like this, 100% of the time, it turned out to be the routing problem. Message me privately, lets do remote later if you have time, I can help you out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 11:50:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129647#M23623</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-17T11:50:41Z</dc:date>
    </item>
    <item>
      <title>Re: SIC and Policy installation in remote checkpoint gateway R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129648#M23624</link>
      <description>&lt;P&gt;Sure, I disabled the anti spoofing on the eth1 interface to allow traffic from 10.x network where my mgmt server is: but this does not look feasible in production. How can I allow internal traffic from a different subnet (other than its own subnet)&amp;nbsp; in checkpoint.&amp;nbsp;&lt;/P&gt;&lt;P&gt;MGMT server (10.x.x.x) &amp;gt;&amp;gt;&amp;gt; eth1 (192.x.x.x) CP&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;eth7 (10.x.x.x) CP&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, with anti spoofing, CP gets traffic and forwards to external interface but while returning, checkpoint kernel forwards the traffic to eth7 instead of eth1 because of same subnet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;how can I control this routing based on a specific source and forward to eth1&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 12:09:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129648#M23624</guid>
      <dc:creator>RajnishR</dc:creator>
      <dc:date>2021-09-17T12:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: SIC and Policy installation in remote checkpoint gateway R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129654#M23625</link>
      <description>&lt;P&gt;I managed to get reverse traffic using PBR on a specific interface&lt;/P&gt;&lt;P&gt;But how I can use 2 networks traffic to one LAN interface (internal) with anti spoofing enabled?&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.x.x.x &amp;amp; 192.x.x.x to eth1 of checkpoint with anti spoofing enabled?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 13:44:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129654#M23625</guid>
      <dc:creator>RajnishR</dc:creator>
      <dc:date>2021-09-17T13:44:54Z</dc:date>
    </item>
    <item>
      <title>Re: SIC and Policy installation in remote checkpoint gateway R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129668#M23627</link>
      <description>&lt;P&gt;You configure the anti-spoofing to allow precisely that configuration?&lt;BR /&gt;It's possible you may also need to disable a specific kernel variable:&amp;nbsp;fw_local_interface_anti_spoofing&lt;BR /&gt;See item 13 here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk22180&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk22180&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Sep 2021 17:32:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129668#M23627</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-17T17:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: SIC and Policy installation in remote checkpoint gateway R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129686#M23629</link>
      <description>&lt;P&gt;Does topology for that interface say "defined by routes" or something different?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 18 Sep 2021 20:04:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129686#M23629</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-09-18T20:04:00Z</dc:date>
    </item>
    <item>
      <title>Re: SIC and Policy installation in remote checkpoint gateway R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129742#M23634</link>
      <description>&lt;P&gt;This is internal interface which get LAN traffic but I want to use this interface to also get mgmt traffic for remote gateways so which mechanism can be applied to this internal interface in order to have 2 specific network traffic allowed with anti spoofing enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently this interface leads to "This network (internal)"&amp;nbsp;&lt;/P&gt;&lt;P&gt;R//&lt;/P&gt;&lt;P&gt;Rajnish&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 06:51:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129742#M23634</guid>
      <dc:creator>RajnishR</dc:creator>
      <dc:date>2021-09-20T06:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: SIC and Policy installation in remote checkpoint gateway R80.40</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129743#M23635</link>
      <description>&lt;P&gt;Thanks experts,&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is solved by using network group in specific section under interface topology &amp;gt; override &amp;gt; specific&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Rajnish&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 07:14:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SIC-and-Policy-installation-in-remote-checkpoint-gateway-R80-40/m-p/129743#M23635</guid>
      <dc:creator>RajnishR</dc:creator>
      <dc:date>2021-09-20T07:14:06Z</dc:date>
    </item>
  </channel>
</rss>

