<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I need help with routing in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68159#M2640</link>
    <description>&lt;P&gt;So those commands that i mentioned do not work apparently, maybe there is something wrong with what i chose for the source,dest,next hop ip values.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Nov 2019 17:45:51 GMT</pubDate>
    <dc:creator>kb1</dc:creator>
    <dc:date>2019-11-22T17:45:51Z</dc:date>
    <item>
      <title>I need help with routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68052#M2632</link>
      <description>&lt;P&gt;So i need to configure routing on my 1100 firewall and below is the information i have for the configuration-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Site subnet: &amp;nbsp;10.40.3.X/24&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Eth LAN2 (vlan20 –secured):&amp;nbsp;10.40.3.21/29; dgw= 10.40.3.20/29 &amp;nbsp;(int Gi0/2)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Eth LAN5 (vlan 10 - unsecured): 10.40.3.11/29, dgw = 10.40.3.10/29 (int Gi0/1)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Source network:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;216.152.218.X/32&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Destination networks:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Checkpoint Portal/Blade - &lt;A href="https://10.169.90.4/sslvpn" target="_blank"&gt;https://10.169.90.4/sslvpn&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 149.122.13.X/32&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 149.122.13.X/32&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 149.122.13.X/32&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what would be the command on cli since i only have console access to configure routing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Fo reference below is the routing configuration for another 1100 appliance and i was told that the routing should be similar to this one-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;# Static routes&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;delete static-routes&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;add static-route service Any destination 10.0.0.X/8 nexthop gateway ipv4-address 10.43.1.20" metric 0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;set static-route 2 service Any destination 10.0.0.X/8 nexthop gateway ipv4-address 10.43.1.20 metric 0 disabled false&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;add static-route service Any destination "216.152.218.X/32" nexthop gateway ipv4-address "10.43.1.X" metric "0"&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;set static-route 3 service Any destination "216.152.218.X/32" nexthop gateway ipv4-address "10.43.1.X" metric "0" disabled "false"&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;add static-route service Any destination "149.122.0.X/16" nexthop gateway ipv4-address "10.43.1.X" metric "0"&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;set static-route 1 service Any destination "149.122.0.X/16" nexthop gateway ipv4-address "10.43.1.X" metric "0" disabled "false"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I cannot figure out what the destination network should be as is shown for above configuration, just keeps showing error and so whenever i try out something.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 19:33:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68052#M2632</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2019-11-21T19:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: I need help with routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68066#M2633</link>
      <description>&lt;P&gt;maybe the destination network has to be any or something?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2019 23:19:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68066#M2633</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2019-11-21T23:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: I need help with routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68080#M2634</link>
      <description>&lt;P&gt;Can you rather &amp;nbsp;draw a network plan ? &amp;nbsp;I seem not to be able to figure it out from what you wrote...&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 08:19:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68080#M2634</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-11-22T08:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: I need help with routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68104#M2635</link>
      <description>&lt;P&gt;&lt;STRONG&gt;add static-route service Any destination "149.122.13.X/32" nexthop gateway ipv4-address "X.X.X.X" metric "1"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Obviously need to replace the X with actual number required which obviously we don't have.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;We won't know the next hop address on your network so cannot tell you what the X need to be&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 10:18:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68104#M2635</guid>
      <dc:creator>mdjmcnally</dc:creator>
      <dc:date>2019-11-22T10:18:33Z</dc:date>
    </item>
    <item>
      <title>Re: I need help with routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68139#M2636</link>
      <description>&lt;P&gt;so the next hop is the dgw specified in my post&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 16:16:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68139#M2636</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2019-11-22T16:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: I need help with routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68140#M2637</link>
      <description>&lt;P&gt;The firewall is on version R77.20 by the way.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 16:17:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68140#M2637</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2019-11-22T16:17:26Z</dc:date>
    </item>
    <item>
      <title>Re: I need help with routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68143#M2638</link>
      <description>&lt;P&gt;so the config that you see is what i received from the telecom team, and this firewall is connected to a switch where the lan 2 port of the firewall is connected to the gi0/2 port of the switch and the lan5 pot is connected to gi0/1 of the switch as shown in the config below, i know that the writing is a bit confusing but yeah thats the info i received-&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Eth LAN2 (vlan20 –secured):&amp;nbsp;10.40.3.21/29; dgw= 10.40.3.20/29 &amp;nbsp;(int Gi0/2)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Eth LAN5 (vlan 10 - unsecured): 10.40.3.11/29, dgw = 10.40.3.10/29 (int Gi0/1)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All i need to configure is the routing for this firewall based on the above info, i tried the add static-route.....&lt;/P&gt;&lt;P&gt;command yesterday but it showed some kind of error, i will try out something today as well to see if it works or not,&lt;/P&gt;&lt;P&gt;so what i beleive is there should be 2 statements for the routes based on the above info. What im planning to implement today is the below commands hopefully they should work-&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;set static-route 1 service any destination any source 10.40.3.21/29 nexthop gateway ipv4-address 10.40.3.20 disabled false metric 0&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;set static-route 2 service any destination any source 10.40.3.11/29 nexthop gateway ipv4-address 10.40.3.10 disabled false metric 0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;And as i mentioned for reference you can look at the routing config for the other 1100 firewall that i shared in the op which does have specific destinations by the way for the static routes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 16:24:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68143#M2638</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2019-11-22T16:24:43Z</dc:date>
    </item>
    <item>
      <title>Re: I need help with routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68147#M2639</link>
      <description>&lt;P&gt;And this part here below i implemented it as a rule in a policy-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Source network:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;216.152.218.X/32&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Destination networks:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Checkpoint Portal/Blade -&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://10.169.90.4/sslvpn" target="_blank" rel="nofollow noopener noreferrer"&gt;https://10.169.90.4/sslvpn&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 149.122.13.X/32&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 149.122.13.X/32&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 149.122.13.X/32&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 16:29:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68147#M2639</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2019-11-22T16:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: I need help with routing</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68159#M2640</link>
      <description>&lt;P&gt;So those commands that i mentioned do not work apparently, maybe there is something wrong with what i chose for the source,dest,next hop ip values.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2019 17:45:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/I-need-help-with-routing/m-p/68159#M2640</guid>
      <dc:creator>kb1</dc:creator>
      <dc:date>2019-11-22T17:45:51Z</dc:date>
    </item>
  </channel>
</rss>

