<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Routing Issue in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/264076#M44568</link>
    <description>&lt;P&gt;The routing change needs to happen at the servers. Alternatively, remove the link to the 3800 cluster from the server LAN and instead connect it to the 9100s on another subnet, so that everything routes via the 9100s.&lt;/P&gt;</description>
    <pubDate>Tue, 02 Dec 2025 05:14:44 GMT</pubDate>
    <dc:creator>emmap</dc:creator>
    <dc:date>2025-12-02T05:14:44Z</dc:date>
    <item>
      <title>Routing Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/263927#M44553</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We are facing routing issue, need your suggestion.&lt;/P&gt;&lt;P&gt;In our environment we are running two CP Cluster 9100 &amp;amp; 3800. Cluster 9100 is used for Internet Traffic &amp;amp; Cluster 3800 is used for IPSec Tunnel Traffic. Both Clusters Gateway intefaces directly connected to DMZ switch.&lt;/P&gt;&lt;P&gt;In DMZ Servers existing gateway ip is 192.168.1.1, which is mentioned in Cluster 9100.&lt;/P&gt;&lt;P&gt;how Remote Office Network traffic which is coming via IPSec Tunnel, can access the DMZ Servers.&lt;/P&gt;&lt;P&gt;What kind of config (routing) we need to perform?&lt;/P&gt;&lt;P&gt;Architecture diagram attached.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 08:12:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/263927#M44553</guid>
      <dc:creator>Mitesh</dc:creator>
      <dc:date>2025-12-01T08:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/263932#M44554</link>
      <description>&lt;P&gt;You may need to look at performing NAT rather than routing depending on the different traffic flows that need to work.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 08:50:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/263932#M44554</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-12-01T08:50:13Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/263973#M44556</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;You have two options.&lt;BR /&gt;&lt;BR /&gt;Configure a static route on the DMZ servers to 192.168.10.0/24 via 192.168.1.6.&lt;BR /&gt;&lt;BR /&gt;Or as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;mentions, configure a NAT rule on the 3800 cluster to hide source 192.168.10.0/24 behind 192.168.1.6.&lt;BR /&gt;This NAT only works for traffic initiated from 192.168.10.0/24. If the DMZ servers initiate traffic to 192.168.10.0/24, you need static destination NAT.&lt;BR /&gt;&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Mon, 01 Dec 2025 14:05:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/263973#M44556</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2025-12-01T14:05:32Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/264069#M44566</link>
      <description>&lt;P&gt;I totally agree with the guys, those suggestions make perfect sense.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 02:11:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/264069#M44566</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-02T02:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/264075#M44567</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3058"&gt;@Martijn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the DMZ Servers initate the traffic, than traffic will forward to 9100 Cluster reason 9100 cluster IP is mentioned as a gateway IP in the DMZ Servers.&lt;/P&gt;&lt;P&gt;In this case what will be the configuration we need to perform in 9100 cluster &amp;amp; 3800 cluster.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 04:33:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/264075#M44567</guid>
      <dc:creator>Mitesh</dc:creator>
      <dc:date>2025-12-02T04:33:28Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/264076#M44568</link>
      <description>&lt;P&gt;The routing change needs to happen at the servers. Alternatively, remove the link to the 3800 cluster from the server LAN and instead connect it to the 9100s on another subnet, so that everything routes via the 9100s.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 05:14:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/264076#M44568</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-12-02T05:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/264080#M44571</link>
      <description>&lt;P&gt;If the DMZ servers need to initiate traffic to 192.168.10.0/24, the simple solution is to add a static route on the DMZ servers. This will route the traffic to 192.168.10.0/24 via the 3800 cluster and the internet traffic to the 9100 cluster. This requires no changes on the 9100 or 3800 cluster.&lt;BR /&gt;&lt;BR /&gt;If changing the route on the DMZ servers is not an option or not possible the solution&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/71054"&gt;@emmap&lt;/a&gt;&amp;nbsp;suggests is a good one. But this requites changes on the 9100 and 3800 cluster in terms of routes and interfaces.&lt;BR /&gt;&lt;BR /&gt;You could go with static (one-on-one) NAT on the 3800 cluster if only a few IP-addresses in the 192.168.10.0/24 subnet should be reached by the DMZ servers. For example:&lt;BR /&gt;&lt;BR /&gt;The DMZ servers need to connect to 192.168.10.10 on the remote location. You can create a NAT rule on the 3800 where destination&amp;nbsp; 192.168.1.10 is NAT-ed to 192.168.10.10. You have to do this for every IP in 192.168.10.0/24 that servers need to connect to (if they initiate the traffic).&lt;BR /&gt;&lt;BR /&gt;This makes it more complex. You need to take care of proxy ARP and it also depends on the application on the server. If the application is programmed to connect to a 192.168.10.x IP, this needs to be changed to a 192.168.1.x IP.&lt;BR /&gt;&lt;BR /&gt;So the most simple option is to add that static route on the DMZ servers.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Dec 2025 06:35:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/264080#M44571</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2025-12-02T06:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Routing Issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/264787#M44625</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3058"&gt;@Martijn&lt;/a&gt;&amp;nbsp;, we have put up the solution in fornt of the managment, waiting for their approval.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2025 06:40:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Routing-Issue/m-p/264787#M44625</guid>
      <dc:creator>Mitesh</dc:creator>
      <dc:date>2025-12-09T06:40:23Z</dc:date>
    </item>
  </channel>
</rss>

