<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISP ClusterXL connection in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227710#M38042</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Sorry, maybe I was not clear. I'm aware of the feature "Cluster IP Addresses on Different Subnets", in fact I've used to configure the /30 on my side. The problem is that the /30 CGNAT network don't have access to the Internet. So, the cluster IP don't have access to the Internet. And that is my issue. The ISP routes a /29 public network to the customer side through the /30, but as far as I know, I cannot NAT the self generated traffic behind that routed network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Tue, 24 Sep 2024 09:04:20 GMT</pubDate>
    <dc:creator>Oryx</dc:creator>
    <dc:date>2024-09-24T09:04:20Z</dc:date>
    <item>
      <title>ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227468#M37988</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I've a problem to solve that is turning my head around for the last couple of weeks. Maye someone have a simple solution for this, since I've tried some different approaches but none has worked as expected.&lt;/P&gt;&lt;P&gt;So, basically I've a couple of 9100 boxes in ClusterXL that I need to connect to the ISP in a particular customer. The ISP connection is delivered through a media coverter and an optional router. Logically, the ISP uses a network in the Carrier Grade NAT space (100.64.x.y/30) and the deliver a public network A.B.C.D/29 through that CGNAT.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right now we have the optional Router receiving the CGNAT network and then Public Network delivered to the ClusterXL through a Private network (192.168.255.0/24). I would like to remove the Router, since it's a single device (lacks redundancy) and it's not quite entrerprise material (lacks performance). I was able to easily remove the router and use the CGNAT network on the ClusterXL. The problem is that the IP on the CGNAT network used on ClusterXL side does not have Internet, which is a big problem, since the Gateways need to connect to the Internet to update IPS, App Control, etc. Also, the Management is a Smart-1 Cloud license :).&lt;/P&gt;&lt;P&gt;So, anyone has had some kind of a related issue? Am I able to remove the router? Or I'm destined to use the router?&lt;/P&gt;&lt;P&gt;Any help is much appreciated on this. I've uploaded a simple network diagram to ilustrate the network topology.&lt;/P&gt;&lt;P&gt;Kind regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2024 11:26:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227468#M37988</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2024-09-22T11:26:28Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227470#M37989</link>
      <description>&lt;P&gt;Just an idea/suggestion...kind of "pondering" here lol. If you say that IP does not have Internet access, can it be NAT-ed to something that does?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2024 14:22:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227470#M37989</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-22T14:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227477#M37992</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/72835"&gt;@Oryx&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Nice scenario. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;For the first sight, maybe do you have the opportunity to configure an existing proxy on the gateways? That would be a great workaround.&lt;/P&gt;
&lt;P&gt;Maybe?&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2024 16:02:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227477#M37992</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-22T16:02:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227478#M37993</link>
      <description>&lt;P&gt;Great idea&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2024 16:04:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227478#M37993</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-22T16:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227480#M37994</link>
      <description>&lt;P&gt;Thanks, this (proxy) saved my life last time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2024 16:15:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227480#M37994</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-22T16:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227482#M37995</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The ISP route to the CGNAT IP on the customer side a /29 Public Network with Internet access. I'm able to NAT traffic transversing my Cluster behind those IPs, but I'm not able to NAT self generated traffic on my gateways, since the VIP of the external interface is the CGNAT IP on customer side. I feel that I'm stuck with the sh**ty router.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2024 16:24:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227482#M37995</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2024-09-22T16:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227485#M37996</link>
      <description>&lt;P&gt;I hear ya, sorry brother...its sadly catch 22 situation.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2024 16:28:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227485#M37996</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-22T16:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227486#M37997</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;That have crossed my mind. However, one of the purposes for this new cluster is to remove from the network an old machine running an old version of Squid. I kinda feel a little bit stupid asking the customer to keep the Squid so the Firewalls can have Internet to keep the services up to date and to connect to the Smart-1 Cloud.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2024 16:32:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227486#M37997</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2024-09-22T16:32:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227490#M37998</link>
      <description>&lt;P&gt;This is really a catch 22. Install a Cloudguard GW for proxy &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2024 16:49:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227490#M37998</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-09-22T16:49:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227494#M37999</link>
      <description>&lt;P&gt;Well, I think whole issue here is how to get an actual IP that can connect to an external world...&lt;/P&gt;</description>
      <pubDate>Sun, 22 Sep 2024 17:03:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227494#M37999</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-22T17:03:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227565#M38016</link>
      <description>&lt;P&gt;With the router in place, what IPs are configured on the external interfaces of the cluster members?&lt;BR /&gt;When you try to eliminate the router, what IPs do you use for the gateways?&lt;/P&gt;
&lt;P&gt;I suspect the router is doing some sort of NAT.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 13:47:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227565#M38016</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-23T13:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227571#M38019</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;When we use the router in place we use a network(192.168.255.0/24) dedicated to connect the router to the Firewalls. The router is the 192.168.255.1 and we have the .251 on FW1, .252 on FW2 and the .254 on the Custer IP VIP.&lt;/P&gt;&lt;P&gt;When we don't have the router, we need to use the CGNAT network to connect to the ISP, which is a /30 network. So, we use a "dummy" network for the physical IPs on the gateways and the IP on the CGNAT network as the Cluster IP, with the proper link local route to have connectivity with the ISP.&lt;/P&gt;&lt;P&gt;And yes, the router is doing NAT when it is in place. The problem is that the CGNAT network does not have Internet, so when we configure that network directly on the Cluster, the Firewalls don't have access to the Internet, since all the traffic generated by the gateways are NATed behind the Cluster IP of the External Interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 14:13:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227571#M38019</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2024-09-23T14:13:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227572#M38020</link>
      <description>&lt;P&gt;Yep, that is the issue.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 14:13:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227572#M38020</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2024-09-23T14:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227573#M38021</link>
      <description>&lt;P&gt;Since Im not even 5% genius compared to&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;, lets see if they have any other ideas. Im just giving my suggestions based on what you are providing here. To me, again, just based on pure logic, unless there is a way to get NAT working to get the routable IP, not sure what else can be done...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 14:16:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227573#M38021</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-23T14:16:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227574#M38022</link>
      <description>&lt;P&gt;Yup, that's it. I'm also out of ideas now. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 14:17:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227574#M38022</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2024-09-23T14:17:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227575#M38023</link>
      <description>&lt;P&gt;Dont lose hope, Im hopeful someone will have a "light bulb moment" &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 14:19:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227575#M38023</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-23T14:19:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227626#M38032</link>
      <description>&lt;P&gt;I assume the /30 is on the far side of the router.&lt;BR /&gt;That means you only have one valid IP address (assuming the other end is your ISP Default Route).&lt;BR /&gt;That means you need to need to use that other IP for your Cluster IP using something like:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ClusterXL_AdminGuide/Content/Topics-CXLG/Cluster-IP-addresses-on-different-subnets.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ClusterXL_AdminGuide/Content/Topics-CXLG/Cluster-IP-addresses-on-different-subnets.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note that only the active cluster member will be able to reach the Internet directly with this configuration.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2024 19:00:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227626#M38032</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-23T19:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227710#M38042</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Sorry, maybe I was not clear. I'm aware of the feature "Cluster IP Addresses on Different Subnets", in fact I've used to configure the /30 on my side. The problem is that the /30 CGNAT network don't have access to the Internet. So, the cluster IP don't have access to the Internet. And that is my issue. The ISP routes a /29 public network to the customer side through the /30, but as far as I know, I cannot NAT the self generated traffic behind that routed network.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 09:04:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227710#M38042</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2024-09-24T09:04:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227766#M38058</link>
      <description>&lt;P&gt;&amp;gt;&amp;nbsp;&lt;SPAN&gt;but as far as I know, I cannot NAT the self generated traffic behind that routed network.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Actually you can but cluster hide/fold which is enabled by default will interfere with your attempts to do so with a rule 0 NAT that takes precedence:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk34180" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk34180: Outgoing connections from cluster members are sent with cluster Virtual IP address instead of member's Physical IP address&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So you'll need to disable cluster hide/fold.&amp;nbsp; This will cause the two members to use their dedicated/fixed CGNAT addresses to initiate connections to the Internet.&amp;nbsp; Now you need to add two manual NAT rules at the top like this, making sure that ExternalZone is properly associated with the outside interface:&lt;/P&gt;
&lt;P&gt;CGNAT Member 1 Ext CGNAT IP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ExternalZone&amp;nbsp; &amp;nbsp; Original&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;/29_Addr_1 (Hide)&amp;nbsp; &amp;nbsp; &amp;nbsp;Original&amp;nbsp; &amp;nbsp; &amp;nbsp;Original&amp;nbsp; &amp;nbsp; &amp;nbsp;Member1&lt;/P&gt;
&lt;P&gt;CGNAT Member 2 Ext CGNAT IP&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ExternalZone&amp;nbsp; &amp;nbsp; Original&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;/29_Addr_2 (Hide)&amp;nbsp; &amp;nbsp; &amp;nbsp;Original&amp;nbsp; &amp;nbsp; &amp;nbsp;Original&amp;nbsp; &amp;nbsp; &amp;nbsp;Member2&lt;/P&gt;
&lt;P&gt;It is possible to NAT firewall-initiated traffic because source NAT happens on the server side between o and O.&amp;nbsp; It is not possible to NAT the destination IP of firewall-initiated traffic as that happens on client side between i and I.&amp;nbsp; You might be able to get away with using a single /29 Internet-routable address for both members as the hide but try using two separate ones first.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 13:53:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227766#M38058</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2024-09-24T13:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISP ClusterXL connection</title>
      <link>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227768#M38059</link>
      <description>&lt;P&gt;Hi Timothy,&lt;/P&gt;&lt;P&gt;I had a kind of supect that something like that was possible to do. It's Check Point, so everything is possible :D. And it seems at least a possibility to proceed.&lt;/P&gt;&lt;P&gt;I just have a little problem scratching my head with that solution. My Management is a Smart-1 Cloud. So, when I make those changes and push the policy to the gateway. Don't you think that I can have a little problem in the middle of the Installation. Do you think that the install will go until de end? Or it will fail because somewhere it that install it will loose access to the Internet?&lt;/P&gt;&lt;P&gt;Kind Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Sep 2024 14:02:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/ISP-ClusterXL-connection/m-p/227768#M38059</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2024-09-24T14:02:23Z</dc:date>
    </item>
  </channel>
</rss>

