<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use specific internal IP for connection from Checkpoint 1430 in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109255#M4759</link>
    <description>&lt;P&gt;In sk119415 we learn about IPSec VPN tunnels peer IPs - you can select using Advanced Settings to use internal IP for VPN tunnels on locally managed SMB, or using fw ctl set int fw_enc_conns_use_internal 1 on centrally Managed SMBs. There is no way to set it to a specific internal IP, but you can try to define a Bridge with the internal IP you want and add all LAN ports (or a Switch with all LAN ports) and WLAN. For outgoing IPSec, this internal IP should be used.&lt;/P&gt;
&lt;P&gt;So please explain which client should start a copy from server to which target ?&lt;/P&gt;</description>
    <pubDate>Fri, 29 Jan 2021 08:44:51 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2021-01-29T08:44:51Z</dc:date>
    <item>
      <title>Use specific internal IP for connection from Checkpoint 1430</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109246#M4758</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;I would like to run a script for copy file from server on checkpoint 1430, but it's accessed from external IP.&lt;/P&gt;&lt;P&gt;In sk119415 was&amp;nbsp;recommended use command fw ctl set int fw_enc_conns_use_internal 1&lt;/P&gt;&lt;P&gt;If you use this command checkpoint, then checkpoint uses any internal IP from its interfaces.&lt;/P&gt;&lt;P&gt;How can I set a specific IP for this purpuse?&lt;/P&gt;&lt;P&gt;Firmware version 77.20.87&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 06:36:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109246#M4758</guid>
      <dc:creator>Basyuk</dc:creator>
      <dc:date>2021-01-29T06:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: Use specific internal IP for connection from Checkpoint 1430</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109255#M4759</link>
      <description>&lt;P&gt;In sk119415 we learn about IPSec VPN tunnels peer IPs - you can select using Advanced Settings to use internal IP for VPN tunnels on locally managed SMB, or using fw ctl set int fw_enc_conns_use_internal 1 on centrally Managed SMBs. There is no way to set it to a specific internal IP, but you can try to define a Bridge with the internal IP you want and add all LAN ports (or a Switch with all LAN ports) and WLAN. For outgoing IPSec, this internal IP should be used.&lt;/P&gt;
&lt;P&gt;So please explain which client should start a copy from server to which target ?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 08:44:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109255#M4759</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-01-29T08:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: Use specific internal IP for connection from Checkpoint 1430</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109259#M4760</link>
      <description>&lt;P&gt;Thank you, but I am not understand method with use Bridge.&lt;/P&gt;&lt;P&gt;For exaple:&lt;/P&gt;&lt;P&gt;My SMB device has a two interfaces with subnet (LAN1 - 10.1.1.1, LAN2 - 172.30.1.1).&lt;BR /&gt;Or SMB has a one interface with two vlans (LAN1.1111 - 10.1.1.1, LAN1.1112 - 172.30.1.1)&lt;/P&gt;&lt;P&gt;I use SmartProvisioning for run script, that writes interfaces configuration to the file and copy this file to my PC (use SCP).&lt;/P&gt;&lt;P&gt;I have the ability to allow access to my PC only from 10.1.1.1.&lt;/P&gt;&lt;P&gt;How can I do it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 09:08:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109259#M4760</guid>
      <dc:creator>Basyuk</dc:creator>
      <dc:date>2021-01-29T09:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: Use specific internal IP for connection from Checkpoint 1430</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109260#M4761</link>
      <description>&lt;P&gt;I am sorry, but i do not understand where the IPSec VPN tunnel comes in here. Bridge is fully covered in the Admin Guide, i would start with it first.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 09:21:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109260#M4761</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-01-29T09:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: Use specific internal IP for connection from Checkpoint 1430</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109261#M4762</link>
      <description>&lt;P&gt;My computer is located behind another checkpoint.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 09:25:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109261#M4762</guid>
      <dc:creator>Basyuk</dc:creator>
      <dc:date>2021-01-29T09:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: Use specific internal IP for connection from Checkpoint 1430</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109262#M4763</link>
      <description>&lt;P&gt;Oh, you want to manipulate the source IP so it does not come from WAN IF but internal SMB IF. Better idea: Let the script send it to a watched client folder in this SMBs local network first and resend it to you from that client 8)&lt;/img&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 09:37:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109262#M4763</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-01-29T09:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: Use specific internal IP for connection from Checkpoint 1430</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109263#M4764</link>
      <description>&lt;P&gt;At this moment I am using the following method:&lt;/P&gt;&lt;P&gt;1. Enable bashUser for admin and run my script in SmartProvisioning&lt;/P&gt;&lt;P&gt;2. Run script from my PC that copy this files to my PC with help putty (pscp)&lt;/P&gt;&lt;P&gt;3. Disable bashUser for admin&lt;/P&gt;&lt;P&gt;I thought there was a way to do it through SmartProvisioning:(&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Jan 2021 09:44:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Use-specific-internal-IP-for-connection-from-Checkpoint-1430/m-p/109263#M4764</guid>
      <dc:creator>Basyuk</dc:creator>
      <dc:date>2021-01-29T09:44:52Z</dc:date>
    </item>
  </channel>
</rss>

