<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Local network settings - Meraki switch connection in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Local-network-settings-Meraki-switch-connection/m-p/219090#M10941</link>
    <description>&lt;P&gt;CP1800, Firmware R81.10, Smart-1 cloud managed&lt;/P&gt;&lt;P&gt;I'm looking for thoughts on the best way to configure a Checkpoint appliance for a Meraki switch network.&lt;/P&gt;&lt;P&gt;I am planning to replace all the Dell switches at one of our large sites;&amp;nbsp; the existing network is a tiered design, so I have OSPF configured on the main core switch to distribute routes to the Checkpoint.&lt;/P&gt;&lt;P&gt;The Dell switch is the main routed core for the network, and the internet uplink is configured as the default route for the network.&lt;/P&gt;&lt;P&gt;I have CP LAN1 configured for the local network access, and the connected switch port is configured as access mode on the core switch.&lt;/P&gt;&lt;P&gt;All pretty straight-forward, however the issue I have discovered is that Meraki 's management network IP address must be separate from the Internet uplink transit network IP address,&amp;nbsp; so I'll have to configure the Checkpoint accordingly.&lt;/P&gt;&lt;P&gt;I am comfortable with the switch config, but I have limited exposure to Checkpoints so I am looking for advise on the best way to connect and configure the Meraki internet uplink - whether that would be separate LAN interfaces, VLAN port, Bridge, etc?&lt;/P&gt;&lt;P&gt;So my options (I think) are as follows:&lt;/P&gt;&lt;P&gt;1. Leave existing LAN1 config for internet access from the Meraki network, and add a second LAN connection for the Meraki Management&lt;/P&gt;&lt;P&gt;Or,&lt;/P&gt;&lt;P&gt;2. Remove the existing config from port LAN1 and recreate as a new VLAN port, with VLANs for management and internet access&lt;/P&gt;&lt;P&gt;I want to try to keep things as simple as possible, so rightly or wrongly, my preference would be to keep the 2 VLANs physically separate with dedicated LAN connections, rather than creating a VLAN trunk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone suggest or recommend the best way to configure this?&lt;/P&gt;&lt;P&gt;Appreciate any help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Jun 2024 11:36:11 GMT</pubDate>
    <dc:creator>AngusM</dc:creator>
    <dc:date>2024-06-28T11:36:11Z</dc:date>
    <item>
      <title>Local network settings - Meraki switch connection</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Local-network-settings-Meraki-switch-connection/m-p/219090#M10941</link>
      <description>&lt;P&gt;CP1800, Firmware R81.10, Smart-1 cloud managed&lt;/P&gt;&lt;P&gt;I'm looking for thoughts on the best way to configure a Checkpoint appliance for a Meraki switch network.&lt;/P&gt;&lt;P&gt;I am planning to replace all the Dell switches at one of our large sites;&amp;nbsp; the existing network is a tiered design, so I have OSPF configured on the main core switch to distribute routes to the Checkpoint.&lt;/P&gt;&lt;P&gt;The Dell switch is the main routed core for the network, and the internet uplink is configured as the default route for the network.&lt;/P&gt;&lt;P&gt;I have CP LAN1 configured for the local network access, and the connected switch port is configured as access mode on the core switch.&lt;/P&gt;&lt;P&gt;All pretty straight-forward, however the issue I have discovered is that Meraki 's management network IP address must be separate from the Internet uplink transit network IP address,&amp;nbsp; so I'll have to configure the Checkpoint accordingly.&lt;/P&gt;&lt;P&gt;I am comfortable with the switch config, but I have limited exposure to Checkpoints so I am looking for advise on the best way to connect and configure the Meraki internet uplink - whether that would be separate LAN interfaces, VLAN port, Bridge, etc?&lt;/P&gt;&lt;P&gt;So my options (I think) are as follows:&lt;/P&gt;&lt;P&gt;1. Leave existing LAN1 config for internet access from the Meraki network, and add a second LAN connection for the Meraki Management&lt;/P&gt;&lt;P&gt;Or,&lt;/P&gt;&lt;P&gt;2. Remove the existing config from port LAN1 and recreate as a new VLAN port, with VLANs for management and internet access&lt;/P&gt;&lt;P&gt;I want to try to keep things as simple as possible, so rightly or wrongly, my preference would be to keep the 2 VLANs physically separate with dedicated LAN connections, rather than creating a VLAN trunk&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone suggest or recommend the best way to configure this?&lt;/P&gt;&lt;P&gt;Appreciate any help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 11:36:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Local-network-settings-Meraki-switch-connection/m-p/219090#M10941</guid>
      <dc:creator>AngusM</dc:creator>
      <dc:date>2024-06-28T11:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: Local network settings - Meraki switch connection</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Local-network-settings-Meraki-switch-connection/m-p/219293#M10965</link>
      <description>&lt;P&gt;You can take one of the LAN ports and assign it to a different network.&lt;BR /&gt;Or you can use the DMZ port for this (if you're not already using it).&lt;BR /&gt;In any case, you can remove the LAN port from the LAN1 switch here (click on Edit):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26554iB201F16D170B9877/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Then you can create a new switch/bridge, assign the network/mask, and add the port to it.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2024 15:45:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Local-network-settings-Meraki-switch-connection/m-p/219293#M10965</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-01T15:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Local network settings - Meraki switch connection</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Local-network-settings-Meraki-switch-connection/m-p/219368#M10977</link>
      <description>&lt;P&gt;Hi, thank you for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am I'm already using my DMZ for guest network access, so it looks like I will have to remove a LAN port to achieve what I require.&lt;/P&gt;&lt;P&gt;I assume that i will have to create firewall rules to allow traffic between these LAN segments, but in what situation would I create a bridge rather than 2 switches?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2024 09:19:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Local-network-settings-Meraki-switch-connection/m-p/219368#M10977</guid>
      <dc:creator>AngusM</dc:creator>
      <dc:date>2024-07-02T09:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Local network settings - Meraki switch connection</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Local-network-settings-Meraki-switch-connection/m-p/219564#M10985</link>
      <description>&lt;P&gt;Yes, you will have to create rules.&lt;BR /&gt;Use cases for bridges include:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Operating as a Layer 2 firewall (bridging WAN and LAN port, for instance)&lt;/LI&gt;
&lt;LI&gt;Having WiFi and LAN ports on the same network&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Wed, 03 Jul 2024 13:36:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Local-network-settings-Meraki-switch-connection/m-p/219564#M10985</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-03T13:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: Local network settings - Meraki switch connection</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Local-network-settings-Meraki-switch-connection/m-p/220382#M11018</link>
      <description>&lt;P&gt;Thank you again - I tested separating the LAN ports as you advised, and it's working as expected &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I also appreciate the info re bridges - we don't have any wireless models so that was confusing me a bit, but the examples you have given make sense now.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2024 10:53:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Local-network-settings-Meraki-switch-connection/m-p/220382#M11018</guid>
      <dc:creator>AngusM</dc:creator>
      <dc:date>2024-07-11T10:53:47Z</dc:date>
    </item>
  </channel>
</rss>

