<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Moving to use VLANs in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Moving-to-use-VLANs/m-p/281875#M46847</link>
    <description>&lt;P&gt;Are you seeing allow/accept logs, possibly an ARP cache/timeout or other L2 issue?&lt;/P&gt;
&lt;P&gt;What type of switches is the VLAN tagged or untagged?&lt;/P&gt;</description>
    <pubDate>Sun, 06 Sep 2026 08:05:22 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2026-09-06T08:05:22Z</dc:date>
    <item>
      <title>Moving to use VLANs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Moving-to-use-VLANs/m-p/281873#M46845</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Checkpoint R82 Jumbo Hotfix Take 122 - 3600 appliance - stand alone not clustered.&lt;/P&gt;&lt;P&gt;I want to reconfigure my LAN to use VLANs.&lt;/P&gt;&lt;P&gt;Currently there is an interface; eth5 with an IP address assigned, 192.168.200.254/24.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the gateway, I remove the IP. I create the first VLAN and give a number; 200 and add the Original IP of the interface, save config.&amp;nbsp; Pop into Smart Console pull down the interfaces with topology and apply policy. All successful.&lt;/P&gt;&lt;P&gt;VLAN 1 and VLAN 200 exist on the internal switch and the connected port is a trunk with access to both VLANs.&lt;/P&gt;&lt;P&gt;Interface eth5,200 now exists with 192.168.200.254/24 assigned.&lt;/P&gt;&lt;P&gt;Routing shows a route, and the route is now linked to the VLAN interface.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Policy allows traffic to and from the 192.168.200/24 subnet.&lt;/P&gt;&lt;P&gt;Yet I can't connect to anything aside from the FW Gateway in that subnet!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone tell me where I am going wrong please?&lt;/P&gt;</description>
      <pubDate>Sat, 05 Sep 2026 23:08:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Moving-to-use-VLANs/m-p/281873#M46845</guid>
      <dc:creator>lphilp01</dc:creator>
      <dc:date>2026-09-05T23:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: Moving to use VLANs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Moving-to-use-VLANs/m-p/281875#M46847</link>
      <description>&lt;P&gt;Are you seeing allow/accept logs, possibly an ARP cache/timeout or other L2 issue?&lt;/P&gt;
&lt;P&gt;What type of switches is the VLAN tagged or untagged?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2026 08:05:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Moving-to-use-VLANs/m-p/281875#M46847</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-09-06T08:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Moving to use VLANs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Moving-to-use-VLANs/m-p/281878#M46848</link>
      <description>&lt;P&gt;HP Instant On 1930 switches&lt;/P&gt;&lt;P&gt;VLAN 1 untagged default to all ports&lt;/P&gt;&lt;P&gt;VLAN 200 tagged all ports&lt;/P&gt;&lt;P&gt;Switch port to FW LAN interface is set as trunk&lt;/P&gt;&lt;P&gt;Nothing seen in logs for my tests at all - I tried ping and https connections to a couple of systems&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 06 Sep 2026 09:49:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Moving-to-use-VLANs/m-p/281878#M46848</guid>
      <dc:creator>lphilp01</dc:creator>
      <dc:date>2026-09-06T09:49:09Z</dc:date>
    </item>
    <item>
      <title>Re: Moving to use VLANs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Moving-to-use-VLANs/m-p/281885#M46849</link>
      <description>&lt;P&gt;Few things I would check, I am assuming you're trying to connect from same network subnet in the same vlan.&lt;BR /&gt;1. Make sure Default gateway/Subnet mask are correctly configured.&lt;BR /&gt;2. Run "fw ctl zdebug + drop" when trying to run traffic see if anything being dropped. (if not the same network could be Anti Spoofing).&lt;BR /&gt;3. if you don't see any drop running the command above it could be a layer 2 issue.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2026 06:13:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Moving-to-use-VLANs/m-p/281885#M46849</guid>
      <dc:creator>Shyyyy</dc:creator>
      <dc:date>2026-09-07T06:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Moving to use VLANs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Moving-to-use-VLANs/m-p/281886#M46850</link>
      <description>&lt;P&gt;What do you see with a packet capture?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2026 07:06:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Moving-to-use-VLANs/m-p/281886#M46850</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2026-09-07T07:06:07Z</dc:date>
    </item>
    <item>
      <title>Re: Moving to use VLANs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Moving-to-use-VLANs/m-p/281901#M46856</link>
      <description>&lt;P&gt;I just want to make sure I'm understanding you correctly first!&lt;/P&gt;&lt;P&gt;Initially, there's a physical interface (eth5), connected to a switchport, the switchport is configured as a trunk port with VLAN1 untagged/native, and VLAN200 tagged, and an IP on the gateway physical interface.&lt;/P&gt;&lt;P&gt;Then the gateway interface is reconfigured so that it is using VLAN200, as eth5.200.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is everything else that you're trying to communicate with on VLAN1 or VLAN200?&lt;/P&gt;&lt;P&gt;Is VLAN1 using a different subnet? (Or is your intent to just lift-and-shift VLAN1 to VLAN200?)&lt;/P&gt;&lt;P&gt;What device is providing inter-VLAN routing between VLAN1 and VLAN200?&lt;/P&gt;&lt;P&gt;You've said that you can't connect to anything else in that subnet apart from the gateway, what are you using to connect to the gateway and how? What other devices exist on the network, and how are they connected? (i.e. by which switch/switchport, and how is that port configured, etc).&lt;/P&gt;&lt;P&gt;Lots of questions I'm afraid!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hesitate to suggest this, but my initial suspicion is that you've moved the 192.168.200.254/24 interface from VLAN1 to VLAN200, and everything else in 192.168.200.0/24 is still in VLAN1, hence the firewall can't see it at all...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Sep 2026 09:45:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Moving-to-use-VLANs/m-p/281901#M46856</guid>
      <dc:creator>Ben_Dunkley</dc:creator>
      <dc:date>2026-09-07T09:45:09Z</dc:date>
    </item>
  </channel>
</rss>

