<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB 770 default route not via WAN interface in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/29552#M1206</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;I filled out a&amp;nbsp;Request for Enhancement for this.&lt;/P&gt;&lt;P&gt;Grtz&lt;/P&gt;&lt;P&gt;Philip&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Jun 2018 09:35:45 GMT</pubDate>
    <dc:creator>Philip_W2</dc:creator>
    <dc:date>2018-06-11T09:35:45Z</dc:date>
    <item>
      <title>SMB 770 default route not via WAN interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/29550#M1204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having trouble&amp;nbsp;setting the default gateway behind another interface but the WAN on my SMB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Background&lt;/P&gt;&lt;P&gt;For our customer's SMB 770 installation&amp;nbsp;I need to use the following interface config:&lt;/P&gt;&lt;P&gt;WAN: DHCP IP&lt;/P&gt;&lt;P&gt;LAN1: fixed IP + by default traffic needs to be routed this way&lt;/P&gt;&lt;P&gt;LAN2: fixed IP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured the following:&lt;/P&gt;&lt;P&gt;1) Internet1 = DHCP, but without "route traffic through this interface by default"&lt;/P&gt;&lt;P&gt;2) LAN2: no issue there, it's just a LAN interface with a connected network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And tried adding the default gateway via LAN1:&lt;/P&gt;&lt;P&gt;1)&amp;nbsp;Configured&amp;nbsp;LAN1 IP in the WebUI (but I'd need to add the default route, which does not accept 0.0.0.0/0).&lt;/P&gt;&lt;P&gt;2) Next I tried adding interface IP and GW via CLI:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;set interface LAN1 ipv4-address x.x.x.x&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;mask-length 24 default-gw&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;x.x.x.y&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Should be simple, but this returns the error "Failed to find the requested interface"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;What am I missing here?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Grtz&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 11.0pt;"&gt;Philip&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 12:45:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/29550#M1204</guid>
      <dc:creator>Philip_W2</dc:creator>
      <dc:date>2018-06-08T12:45:24Z</dc:date>
    </item>
    <item>
      <title>Re: SMB 770 default route not via WAN interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/29551#M1205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The LAN interface cannot be used as the default route on SMB appliances.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Jun 2018 19:46:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/29551#M1205</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-06-08T19:46:15Z</dc:date>
    </item>
    <item>
      <title>Re: SMB 770 default route not via WAN interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/29552#M1206</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;Thanks for your answer.&lt;/P&gt;&lt;P&gt;I filled out a&amp;nbsp;Request for Enhancement for this.&lt;/P&gt;&lt;P&gt;Grtz&lt;/P&gt;&lt;P&gt;Philip&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Jun 2018 09:35:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/29552#M1206</guid>
      <dc:creator>Philip_W2</dc:creator>
      <dc:date>2018-06-11T09:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: SMB 770 default route not via WAN interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/29553#M1207</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Had similar issue, no Internet connection configured at all.&lt;/P&gt;&lt;P&gt;This is how you solve this issue, let say the nexthop is 10.10.1.15, you just create 2 routes:&lt;/P&gt;&lt;P&gt;add static-route destination 0.0.0.0/1 nexthop gateway ipv4-address &lt;SPAN&gt;10.10.1.15&lt;/SPAN&gt;&lt;BR /&gt;add static-route destination 128.0.0.0/1 nexthop gateway ipv4-address &lt;SPAN&gt;10.10.1.15&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Effectively this is 2 half default routes adding up to a default route.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The error about the Interface could be related to the LAN1_Switch, to remove use the following:&lt;/P&gt;&lt;P&gt;delete switch LAN1_Switch&lt;BR /&gt;set dhcp server interface LAN1 disable&lt;BR /&gt;set interface LAN1 unassigned&lt;BR /&gt;set interface LAN1 ipv4-address 10.10.1.1 mask-length 29 state on&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jun 2018 20:41:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/29553#M1207</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2018-06-18T20:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: SMB 770 default route not via WAN interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/29554#M1208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thx Maarten, I'll definitely try that when the issue comes along again!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2018 06:02:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/29554#M1208</guid>
      <dc:creator>Philip_W2</dc:creator>
      <dc:date>2018-06-19T06:02:00Z</dc:date>
    </item>
    <item>
      <title>Re: SMB 770 default route not via WAN interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/74154#M2944</link>
      <description>Thanks Maarten for the hint, that's ingenious and worked great.&lt;BR /&gt;&lt;BR /&gt;Had this issue with the 1430 appliances...if you're not using the WAN interface you can't setup a default route.&lt;BR /&gt;Even if you did enter it manually as 0.0.0.0/8, it would come up as dynamic and would not be used.&lt;BR /&gt;&lt;BR /&gt;IMHO setting a default route shouldn't need such artifacts though.</description>
      <pubDate>Tue, 04 Feb 2020 21:15:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/74154#M2944</guid>
      <dc:creator>Constantin_Pop</dc:creator>
      <dc:date>2020-02-04T21:15:38Z</dc:date>
    </item>
    <item>
      <title>Re: SMB 770 default route not via WAN interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/74155#M2945</link>
      <description>It's just to bad, but even in R80.20 on the 15x0 it is still not possible to create a Default route on a LAN port.</description>
      <pubDate>Tue, 04 Feb 2020 21:26:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/74155#M2945</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-02-04T21:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: SMB 770 default route not via WAN interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/74158#M2946</link>
      <description>That's nice for such a basic feature.&lt;BR /&gt;I tried finding this limitation in the docs but doesn't show up anywhere.</description>
      <pubDate>Tue, 04 Feb 2020 21:39:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/74158#M2946</guid>
      <dc:creator>Constantin_Pop</dc:creator>
      <dc:date>2020-02-04T21:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: SMB 770 default route not via WAN interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/204202#M10178</link>
      <description>&lt;P&gt;If you plan to follow these steps, do not use the "state on" at the end of the command:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;set interface LAN1 ipv4-address 10.10.1.1 mask-length 29 state on&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Using state on will result in the firewall not setting the IP. (1800 SMB r81.x.x)&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 21:27:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-770-default-route-not-via-WAN-interface/m-p/204202#M10178</guid>
      <dc:creator>Jose_Garza</dc:creator>
      <dc:date>2024-01-25T21:27:22Z</dc:date>
    </item>
  </channel>
</rss>

