<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic internet access through firewall in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/internet-access-through-firewall/m-p/242676#M40566</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a netis router with ip 172.20.10.2 and gateway 172.20.10.1 , also i have firewall sg3600 with mgnt ip 192.168.1.1 , eth1 ip192.168.4.1 and eth2 ip 192.168.5.2 . i want to deploy this firewall and have internet access in my laptop.&lt;/P&gt;&lt;P&gt;What i did is :&lt;/P&gt;&lt;P&gt;Log in to Netis Router (&lt;A href="http://172.20.10.2" target="_blank" rel="noopener"&gt;http://172.20.10.2&lt;/A&gt;)&lt;BR /&gt;Go to: Network &amp;gt; Routing&lt;/P&gt;&lt;P&gt;&amp;nbsp;Add a static route:&lt;/P&gt;&lt;P&gt;Destination: 192.168.4.0&lt;BR /&gt;Subnet Mask: 255.255.255.0&lt;BR /&gt;Gateway: 192.168.5.2 (Firewall eth2)&lt;/P&gt;&lt;H3&gt;&lt;FONT size="2"&gt;Add Static Route in Gaia WebUI&lt;/FONT&gt;&lt;/H3&gt;&lt;P&gt;&lt;FONT size="2"&gt;Login to Check Point Gaia WebUI (&lt;A href="https://192.168.1.1" target="_blank" rel="noopener"&gt;https://192.168.1.1&lt;/A&gt;).&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Go to: Network Management &amp;gt; IPv4 Static Routes.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Add the following routes:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Route for Internet traffic:&lt;/FONT&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Destination: 0.0.0.0/0&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Gateway: 172.20.10.1 (Netis Router Gateway)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Interface: eth2&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Route for LAN traffic:&lt;/FONT&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Destination: 192.168.4.0/24&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Gateway: 192.168.4.1 (Firewall eth1)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Interface: eth1&lt;/FONT&gt;&lt;BR /&gt;&lt;H3&gt;&lt;FONT size="2"&gt;Configure Hide NAT in SmartConsole&lt;/FONT&gt;&lt;/H3&gt;&lt;P&gt;&lt;FONT size="2"&gt;Open SmartConsole → Security Policy → NAT.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Add a new Hide NAT Rule:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Original Source: 192.168.4.0/24 (Internal network)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Original Destination: Any&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Service: Any&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Translated Source: 192.168.5.2 (Firewall eth2 IP) &lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Save &amp;amp; Install Policy.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;&lt;FONT size="2"&gt;Step 4: Set Laptop Network Configuration&lt;/FONT&gt;&lt;/H2&gt;&lt;P&gt;&lt;FONT size="2"&gt;Your laptop must use the firewall’s eth1 IP (192.168.4.1) as the default gateway.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;Go to Network Settings on Laptop&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Set Static IP:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="2"&gt;IP Address: 192.168.4.100&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Subnet Mask: 255.255.255.0&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Default Gateway: 192.168.4.1 (Firewall eth1)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;DNS Server: 8.8.8.8 (Google DNS) Save &amp;amp; Restart Network.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;&lt;FONT size="2"&gt;Configure Security Policy in SmartConsole&lt;/FONT&gt;&lt;/H2&gt;&lt;P&gt;&lt;FONT size="2"&gt;The firewall must allow traffic from eth2 (WAN) to eth1 (LAN).&lt;/FONT&gt;&lt;/P&gt;&lt;H3&gt;&lt;FONT size="2"&gt;Add Access Control Rule in SmartConsole&lt;/FONT&gt;&lt;/H3&gt;&lt;P&gt;&lt;FONT size="2"&gt;Go to SmartConsole → Security Policy &amp;gt; Access Control.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Create a New Rule:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Source: 192.168.4.0/24 (Internal network)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Destination: Any&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Service: Any&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Action: Accept Save &amp;amp; Install Policy.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;On firewall SSH i can ping netis router , but cannot ping internet 8.8.8.8.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Fri, 28 Feb 2025 14:40:56 GMT</pubDate>
    <dc:creator>lcako</dc:creator>
    <dc:date>2025-02-28T14:40:56Z</dc:date>
    <item>
      <title>internet access through firewall</title>
      <link>https://community.checkpoint.com/t5/General-Topics/internet-access-through-firewall/m-p/242676#M40566</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a netis router with ip 172.20.10.2 and gateway 172.20.10.1 , also i have firewall sg3600 with mgnt ip 192.168.1.1 , eth1 ip192.168.4.1 and eth2 ip 192.168.5.2 . i want to deploy this firewall and have internet access in my laptop.&lt;/P&gt;&lt;P&gt;What i did is :&lt;/P&gt;&lt;P&gt;Log in to Netis Router (&lt;A href="http://172.20.10.2" target="_blank" rel="noopener"&gt;http://172.20.10.2&lt;/A&gt;)&lt;BR /&gt;Go to: Network &amp;gt; Routing&lt;/P&gt;&lt;P&gt;&amp;nbsp;Add a static route:&lt;/P&gt;&lt;P&gt;Destination: 192.168.4.0&lt;BR /&gt;Subnet Mask: 255.255.255.0&lt;BR /&gt;Gateway: 192.168.5.2 (Firewall eth2)&lt;/P&gt;&lt;H3&gt;&lt;FONT size="2"&gt;Add Static Route in Gaia WebUI&lt;/FONT&gt;&lt;/H3&gt;&lt;P&gt;&lt;FONT size="2"&gt;Login to Check Point Gaia WebUI (&lt;A href="https://192.168.1.1" target="_blank" rel="noopener"&gt;https://192.168.1.1&lt;/A&gt;).&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Go to: Network Management &amp;gt; IPv4 Static Routes.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Add the following routes:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Route for Internet traffic:&lt;/FONT&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Destination: 0.0.0.0/0&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Gateway: 172.20.10.1 (Netis Router Gateway)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Interface: eth2&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Route for LAN traffic:&lt;/FONT&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Destination: 192.168.4.0/24&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Gateway: 192.168.4.1 (Firewall eth1)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Interface: eth1&lt;/FONT&gt;&lt;BR /&gt;&lt;H3&gt;&lt;FONT size="2"&gt;Configure Hide NAT in SmartConsole&lt;/FONT&gt;&lt;/H3&gt;&lt;P&gt;&lt;FONT size="2"&gt;Open SmartConsole → Security Policy → NAT.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Add a new Hide NAT Rule:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Original Source: 192.168.4.0/24 (Internal network)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Original Destination: Any&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Service: Any&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Translated Source: 192.168.5.2 (Firewall eth2 IP) &lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Save &amp;amp; Install Policy.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;&lt;FONT size="2"&gt;Step 4: Set Laptop Network Configuration&lt;/FONT&gt;&lt;/H2&gt;&lt;P&gt;&lt;FONT size="2"&gt;Your laptop must use the firewall’s eth1 IP (192.168.4.1) as the default gateway.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;Go to Network Settings on Laptop&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Set Static IP:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="2"&gt;IP Address: 192.168.4.100&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Subnet Mask: 255.255.255.0&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Default Gateway: 192.168.4.1 (Firewall eth1)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;DNS Server: 8.8.8.8 (Google DNS) Save &amp;amp; Restart Network.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H2&gt;&lt;FONT size="2"&gt;Configure Security Policy in SmartConsole&lt;/FONT&gt;&lt;/H2&gt;&lt;P&gt;&lt;FONT size="2"&gt;The firewall must allow traffic from eth2 (WAN) to eth1 (LAN).&lt;/FONT&gt;&lt;/P&gt;&lt;H3&gt;&lt;FONT size="2"&gt;Add Access Control Rule in SmartConsole&lt;/FONT&gt;&lt;/H3&gt;&lt;P&gt;&lt;FONT size="2"&gt;Go to SmartConsole → Security Policy &amp;gt; Access Control.&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;Create a New Rule:&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Source: 192.168.4.0/24 (Internal network)&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Destination: Any&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Service: Any&lt;/FONT&gt;&lt;/LI&gt;&lt;LI&gt;&lt;FONT size="2"&gt;Action: Accept Save &amp;amp; Install Policy.&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;On firewall SSH i can ping netis router , but cannot ping internet 8.8.8.8.&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 28 Feb 2025 14:40:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/internet-access-through-firewall/m-p/242676#M40566</guid>
      <dc:creator>lcako</dc:creator>
      <dc:date>2025-02-28T14:40:56Z</dc:date>
    </item>
  </channel>
</rss>

