<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing between subnets in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206072#M34191</link>
    <description>&lt;P&gt;applance is box 1550&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Version:&lt;/TD&gt;&lt;TD&gt;R81.10.08&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Wed, 14 Feb 2024 12:50:50 GMT</pubDate>
    <dc:creator>JJezek</dc:creator>
    <dc:date>2024-02-14T12:50:50Z</dc:date>
    <item>
      <title>Routing between subnets</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/205906#M34170</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;can you help me. I can't set up routing between 2 separate site interfaces.&lt;/P&gt;&lt;P&gt;I have office lan 10.0.0.138/24 on LAN1:10.0.0.138&lt;BR /&gt;and CMS lan 198.19.133.80 on LAN4: 198.19.133.82 (198.19.133.81 is a T-mobile modem). I cannot reach the T-mobile IP (198.19.133.81) from the office network.&amp;nbsp; I set the object group and put them in the policy, But the communication does not work. ping to the IP address of the modem only works with FW checkpoint. I am attaching a picture for clarification.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR Jaroslav&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 11:58:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/205906#M34170</guid>
      <dc:creator>JJezek</dc:creator>
      <dc:date>2024-02-13T11:58:56Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between subnets</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/205950#M34178</link>
      <description>&lt;P&gt;I think t-mobile modem does not know how to route 10.0.0.0/24 back to the CP.&lt;/P&gt;
&lt;P&gt;What does tcpdump -nni LAN4 host&amp;nbsp;198.19.133.81&amp;nbsp; , show when you send traffic from the LAN?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 14:55:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/205950#M34178</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-02-13T14:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between subnets</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/205955#M34179</link>
      <description>&lt;P&gt;How is any NAT configured / defined in the existing setup and which appliance firmware version/build?&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 15:04:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/205955#M34179</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-02-13T15:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between subnets</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/205964#M34180</link>
      <description>&lt;P&gt;Did you do any captures/debugs to see whats happening with the traffic?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 15:45:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/205964#M34180</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-13T15:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between subnets</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206020#M34186</link>
      <description>&lt;P&gt;Hi Lesley,&amp;nbsp;&amp;nbsp;Thank you for your response.&lt;/P&gt;&lt;P&gt;I tried setting up monitoring. There is a syntax error. I spoke with the technician who was setting up the T-mobile router. He told me that on CP I should have S-NAT for office lan 10.0.0.0/24 to IP address 198.19.133.82 (LAN4 port) when requesting communication to CMS 10.240.0.0/12. CMS 10.240.0.0/12 is a closed network that is only reachable from the 198.19.133.80/29 network.&lt;/P&gt;&lt;P&gt;I am afraid that it will be necessary to turn off the default hidden NAT on CP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The CPS network is&amp;nbsp;reachable now only from CP from tool.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR Jaroslav&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 08:25:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206020#M34186</guid>
      <dc:creator>JJezek</dc:creator>
      <dc:date>2024-02-14T08:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between subnets</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206024#M34187</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;The natu configuration is the default. A hidden nat that masks the office to one WAN. That can be ten problems. I need to mask part of the traffic from the office LAN behind an IP from the range 198.19.133.80/29, i.e. for IP LAN4 198.19.133.82 ? This is what the Tmobile technician told me and the second thing is to set the route. 10.240.0.0/12 next hop 198.19.133.81.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR Jaroslav&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 08:33:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206024#M34187</guid>
      <dc:creator>JJezek</dc:creator>
      <dc:date>2024-02-14T08:33:15Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between subnets</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206072#M34191</link>
      <description>&lt;P&gt;applance is box 1550&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Version:&lt;/TD&gt;&lt;TD&gt;R81.10.08&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Wed, 14 Feb 2024 12:50:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206072#M34191</guid>
      <dc:creator>JJezek</dc:creator>
      <dc:date>2024-02-14T12:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between subnets</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206075#M34192</link>
      <description>&lt;P&gt;HI Andy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I only have one log where I try to ping IP 10.250.142.198 to the CMS subnet for testing. I would need the office LAN 10.0.0./24 in this case the IP from the server 10.0.0.250 to be masked behind the IP from the range 198.19.133.80/29. This is enforced by CMS as a condition.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 13:12:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206075#M34192</guid>
      <dc:creator>JJezek</dc:creator>
      <dc:date>2024-02-14T13:12:01Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between subnets</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206078#M34193</link>
      <description>&lt;P&gt;LOG:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tcpdump: verbose output suppressed, use -v or -vv for full protocol decode&lt;BR /&gt;listening on LAN4, link-type EN10MB (Ethernet), capture size 262144 bytes&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;BR /&gt;IP 10.0.0.251 &amp;gt; 10.250.142.198: ICMP echo request, id 1, seq 20916, length 40&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;BR /&gt;IP 10.0.0.251 &amp;gt; 10.250.142.198: ICMP echo request, id 1, seq 20917, length 40&lt;BR /&gt;ARP, Request who-has 198.19.133.81 tell 198.19.133.82, length 28&lt;BR /&gt;ARP, Reply 198.19.133.81 is-at e4:77:27:1b:ec:7c, length 46&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;BR /&gt;IP 10.0.0.251 &amp;gt; 10.250.142.198: ICMP echo request, id 1, seq 20918, length 40&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;BR /&gt;IP 10.0.0.251 &amp;gt; 10.250.142.198: ICMP echo request, id 1, seq 20919, length 40&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;BR /&gt;IP 10.0.0.251 &amp;gt; 10.250.142.198: ICMP echo request, id 1, seq 20920, length 40&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;BR /&gt;STP 802.1w, Rapid STP, Flags [Learn, Forward, Agreement], bridge-id 8000.e4:77:27:1b:ec:7c.8001, length 43&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 13:13:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206078#M34193</guid>
      <dc:creator>JJezek</dc:creator>
      <dc:date>2024-02-14T13:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between subnets</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206413#M34238</link>
      <description>&lt;P&gt;SOLVED by source NAT&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2024 10:33:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206413#M34238</guid>
      <dc:creator>JJezek</dc:creator>
      <dc:date>2024-02-19T10:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: Routing between subnets</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206425#M34241</link>
      <description>&lt;P&gt;Good job!&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 19 Feb 2024 14:44:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-between-subnets/m-p/206425#M34241</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-19T14:44:06Z</dc:date>
    </item>
  </channel>
</rss>

