<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 1800 SMB set source ip for connections originating from cluster in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140074#M6295</link>
    <description>&lt;P&gt;Let's cover basics first. Version, locally or centrally managed?&lt;/P&gt;</description>
    <pubDate>Tue, 01 Feb 2022 11:09:36 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2022-02-01T11:09:36Z</dc:date>
    <item>
      <title>1800 SMB set source ip for connections originating from cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140069#M6294</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I am trying to figure out how the connections are originated from checkpoint SMBs.&lt;/P&gt;&lt;P&gt;I have a scenario. I am using RADIUS authentication for RA VPN and the radius packets towards customer LAN (where the radius server is) are sourced from the SYNC subnet (subnet that is used for cluster sync). Usually, the customer LAN would be directly connected and source IP would be from this subnet, but in my case cust. subnet 10.3.0.0/24 is routed over another p2p subnet because we are in migration phase. As a result my connection is sourced from IP of the wrong interface (LAN2/SYNC).&lt;/P&gt;&lt;P&gt;How can I change the source IP of the radius auth requests? Source NAT does not work (I am using strict&amp;nbsp; fw rules and automatic hide NAT is off). Boxes are locally managed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;10:17:56.073707 IP my.firewall.58523 &amp;gt; 10.3.0.96.radius: RADIUS, Access-Request (1), id: 0xde length: 56&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10:18:01.075881 IP my.firewall.58523 &amp;gt; 10.3.0.96.radius: RADIUS, Access-Request (1), id: 0xde length: 56&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;10:18:06.077731 IP my.firewall.58523 &amp;gt; 10.3.0.96.radius: RADIUS, Access-Request (1), id: 0xde length: 56&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;# ping my.firewall&lt;BR /&gt;PING my.firewall (10.231.149.1): 56 data bytes&lt;BR /&gt;64 bytes from 10.231.149.1: seq=0 ttl=64 time=0.062 ms&lt;BR /&gt;64 bytes from 10.231.149.1: seq=1 ttl=64 time=0.057 ms&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 10:08:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140069#M6294</guid>
      <dc:creator>vladdar</dc:creator>
      <dc:date>2022-02-01T10:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: 1800 SMB set source ip for connections originating from cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140074#M6295</link>
      <description>&lt;P&gt;Let's cover basics first. Version, locally or centrally managed?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 11:09:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140074#M6295</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-02-01T11:09:36Z</dc:date>
    </item>
    <item>
      <title>Re: 1800 SMB set source ip for connections originating from cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140076#M6296</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The current firmware version is&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;R80.20.35 (992002577)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;locally managed&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 11:43:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140076#M6296</guid>
      <dc:creator>vladdar</dc:creator>
      <dc:date>2022-02-01T11:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: 1800 SMB set source ip for connections originating from cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140077#M6297</link>
      <description>&lt;P&gt;Thank you. So what is the problem, RADIUS does not recognise those different IPs? Or something else?&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 12:03:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140077#M6297</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-02-01T12:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: 1800 SMB set source ip for connections originating from cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140078#M6298</link>
      <description>&lt;P&gt;Problem is that it is inconvenient because of the administration overhead. Customer has to allow and route new subnet. Subnet which should be used just for the interconnection of the cluster members.&lt;/P&gt;&lt;P&gt;This does not make sense to source connections from those IPs.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 12:06:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140078#M6298</guid>
      <dc:creator>vladdar</dc:creator>
      <dc:date>2022-02-01T12:06:30Z</dc:date>
    </item>
    <item>
      <title>Re: 1800 SMB set source ip for connections originating from cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140079#M6299</link>
      <description>&lt;P&gt;Source IPs are based on interfaces used to communicate with the server. When and if you change the topology and eliminate the network in the middle, it should be back to normal.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 12:11:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140079#M6299</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-02-01T12:11:32Z</dc:date>
    </item>
    <item>
      <title>Re: 1800 SMB set source ip for connections originating from cluster</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140080#M6300</link>
      <description>&lt;P&gt;Yes I am counting on that.. But this: "&lt;SPAN&gt;Source IPs are based on interfaces used to communicate with the server" is not true right know. p2p interface towards customer is LANBOND0.3 interface and that is where the route towards server points and i would assume this would be the source of the connection but actually the source is SYNC interconnection interface between cluster members which is very weird. But if it cannot be change of course workaround is possible, it's just inconvenient.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks Val.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Feb 2022 12:30:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1800-SMB-set-source-ip-for-connections-originating-from-cluster/m-p/140080#M6300</guid>
      <dc:creator>vladdar</dc:creator>
      <dc:date>2022-02-01T12:30:21Z</dc:date>
    </item>
  </channel>
</rss>

