<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About Checkpoint's Bridge Mode Constraints in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/About-Checkpoint-s-Bridge-Mode-Constraints/m-p/199835#M33379</link>
    <description>&lt;P&gt;In general it means a given bridge e.g. br1 is comprised of two interfaces "1A" and "1B"&lt;/P&gt;
&lt;P&gt;To help could you please clarify your diagram some...&lt;/P&gt;
&lt;P&gt;Is there only one subnet between the Layer-3 switch and the routers shown or is each on it's own subnet / VLAN?&lt;/P&gt;</description>
    <pubDate>Wed, 06 Dec 2023 08:57:31 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2023-12-06T08:57:31Z</dc:date>
    <item>
      <title>About Checkpoint's Bridge Mode Constraints</title>
      <link>https://community.checkpoint.com/t5/General-Topics/About-Checkpoint-s-Bridge-Mode-Constraints/m-p/199831#M33378</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;&lt;P&gt;We're thinking of a IPS configuration for monitering IoT communication and PC communication.&lt;/P&gt;&lt;P&gt;If Quantum is installed between L3SW and L2Sw as an IPS, is it possible to configure it as follows?&lt;/P&gt;&lt;P&gt;I would like to run Quantum in bridge mode (L2), but since the URL below says "Important - Only two interfaces can be connected by one Bridge interface", I don't think it can meet the requirements in bridge mode, am I right?&lt;/P&gt;&lt;P&gt;If you know of any best practices or proven methods using checkpoints, please let me know.&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sample.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23552iBEAA09D87476065E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sample.PNG" alt="sample.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 08:14:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/About-Checkpoint-s-Bridge-Mode-Constraints/m-p/199831#M33378</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2023-12-06T08:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: About Checkpoint's Bridge Mode Constraints</title>
      <link>https://community.checkpoint.com/t5/General-Topics/About-Checkpoint-s-Bridge-Mode-Constraints/m-p/199835#M33379</link>
      <description>&lt;P&gt;In general it means a given bridge e.g. br1 is comprised of two interfaces "1A" and "1B"&lt;/P&gt;
&lt;P&gt;To help could you please clarify your diagram some...&lt;/P&gt;
&lt;P&gt;Is there only one subnet between the Layer-3 switch and the routers shown or is each on it's own subnet / VLAN?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 08:57:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/About-Checkpoint-s-Bridge-Mode-Constraints/m-p/199835#M33379</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-06T08:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: About Checkpoint's Bridge Mode Constraints</title>
      <link>https://community.checkpoint.com/t5/General-Topics/About-Checkpoint-s-Bridge-Mode-Constraints/m-p/199850#M33381</link>
      <description>&lt;P&gt;Thank you for the reply.&lt;/P&gt;&lt;P&gt;Our environment aggregates routing to L3SW. Therefore, the router, L3SW, IOT devices and computers at the headquarters belong to the same network. Of course, branches have different networks.　&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The diagram is shown below.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sample2.PNG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23555iAE8AC07BC4FA0B09/image-size/medium?v=v2&amp;amp;px=400" role="button" title="sample2.PNG" alt="sample2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 09:40:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/About-Checkpoint-s-Bridge-Mode-Constraints/m-p/199850#M33381</guid>
      <dc:creator>TSOL</dc:creator>
      <dc:date>2023-12-06T09:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: About Checkpoint's Bridge Mode Constraints</title>
      <link>https://community.checkpoint.com/t5/General-Topics/About-Checkpoint-s-Bridge-Mode-Constraints/m-p/199854#M33384</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have to be wary of double inspecting any traffic flows, so with this in mind the only potential solution that comes to mind involves additional cabling and running the firewall as VSX to partition the segments.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Suggest engaging your local SE to help you validate possible options and engage with solution center if needed.&lt;/P&gt;
&lt;P&gt;By contrast implementing the links to the routers via an intermediate switch helps from a plumbing perspective but creates a visibility issue.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Dec 2023 11:00:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/About-Checkpoint-s-Bridge-Mode-Constraints/m-p/199854#M33384</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-06T11:00:34Z</dc:date>
    </item>
  </channel>
</rss>

