<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route Default GW not via WAN interface but via sub-vlan interface in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155361#M7259</link>
    <description>&lt;P&gt;Yes correct Chris. On the same single (trunk) port i will configured one vlan to route over internet and one other vlan as internal network. I know this can be easily done with making 2 separate physical interfaces one (WAN) and one (LAN). But just want to confirm first if there is a way to make this setup or not? because if there is no way then i will go to the original plan to use 2 physical interfaces instead. just to note i am using SMB device 1450 on a cluster.&lt;/P&gt;&lt;P&gt;Please let me know how it goes then.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Aug 2022 04:17:13 GMT</pubDate>
    <dc:creator>mrknthny</dc:creator>
    <dc:date>2022-08-22T04:17:13Z</dc:date>
    <item>
      <title>Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155246#M7243</link>
      <description>&lt;P&gt;Hi All, hope someone can help me.&lt;/P&gt;&lt;P&gt;I am having a setup to configure trunk on an interface (either WAN or LAN). But this interface need to be configured as trunk and create sub-vlan interfaces. To put simply, say&lt;/P&gt;&lt;P&gt;LAN 1&lt;/P&gt;&lt;P&gt;LAN1.2 (vlan 2): 192.168.29.0/24&lt;/P&gt;&lt;P&gt;LAN1.3 (vlan 3): 192.168.30.0/24&lt;/P&gt;&lt;P&gt;Then say, I want to create the default route via LAN1.2. Is there a way I can do that?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If I create LAN1 as internet, it doesnt allow me to create sub-interfaces. If i create LAN1 as normal LAN port and create sub-vlan interfaces, it knows that the WAN (default) should have the default route since it is the internet gateway.&lt;/P&gt;&lt;P&gt;I am using SMB device 1450 series in cluster.&lt;/P&gt;&lt;P&gt;If there is no way, then i guess I will just use two interfaces on my device, one WAN and one LAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 01:22:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155246#M7243</guid>
      <dc:creator>mrknthny</dc:creator>
      <dc:date>2022-08-19T01:22:17Z</dc:date>
    </item>
    <item>
      <title>Re: Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155305#M7250</link>
      <description>&lt;P&gt;Have you tried the configuration on the DMZ port?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DMZ_Internet.png" style="width: 692px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17478i10186B1FE302C1F1/image-size/large?v=v2&amp;amp;px=999" role="button" title="DMZ_Internet.png" alt="DMZ_Internet.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 03:58:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155305#M7250</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-22T03:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155307#M7251</link>
      <description>&lt;P&gt;Hi Chris,&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for replying. I have not tried yet. As I tried on port WAN and LAN ports but just wouldn't work. May I know if you have tried the setup before? I will give your suggestion a try. Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2022 14:55:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155307#M7251</guid>
      <dc:creator>mrknthny</dc:creator>
      <dc:date>2022-08-19T14:55:26Z</dc:date>
    </item>
    <item>
      <title>Re: Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155332#M7254</link>
      <description>&lt;P&gt;On Gaia Embedded You must have the default GW on the WAN interface or a bond interface that contains the WAN interface.&lt;/P&gt;&lt;P&gt;I also faced a topology like yours, and there was no way to make it work properly, if there is no link up on the WAN interface even the IPS will not work for you, you can check it with the command "ips stat "&lt;/P&gt;</description>
      <pubDate>Sat, 20 Aug 2022 18:28:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155332#M7254</guid>
      <dc:creator>AngelettaA</dc:creator>
      <dc:date>2022-08-20T18:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155334#M7255</link>
      <description>&lt;P&gt;Hi AngelettaA,&lt;/P&gt;&lt;P&gt;thank you for your response. Agree. But It doesnt necessarily need to be on a Wan interface. We can use a Lan interface as long as you set the lan interface as the internet it will use that as the interface for default gateway. But the problem happens when I need to trunk the interface, it wont allow me to use any sub-interface as a route for default gateway. Port only needs to be a normal wan/lan port.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 21 Aug 2022 00:54:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155334#M7255</guid>
      <dc:creator>mrknthny</dc:creator>
      <dc:date>2022-08-21T00:54:06Z</dc:date>
    </item>
    <item>
      <title>Re: Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155358#M7256</link>
      <description>&lt;P&gt;Note Bond interfaces are not supported on 1400 series appliances per&amp;nbsp;&lt;SPAN&gt;sk114217.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 04:03:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155358#M7256</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-22T04:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155359#M7257</link>
      <description>&lt;P&gt;To be clear your requirement is not only to have the Internet over a VLAN but also on the same single (trunk) port as the Internal networks?&lt;/P&gt;
&lt;P&gt;I don't believe the Web UI allows such a configuration but will test via CLI and update here.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 04:06:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155359#M7257</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-22T04:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155360#M7258</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;i have not yet, only tried on WAN and LAN interfaces so far (which havent worked obviously) but am keen to give this (DMZ) a try tomorrow and will update you. Once i have configured this, do i need to configure manual default route? or will it be automatically created based on which vlan i want to be routed as the internet gateway?\&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Cheers!&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 04:07:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155360#M7258</guid>
      <dc:creator>mrknthny</dc:creator>
      <dc:date>2022-08-22T04:07:14Z</dc:date>
    </item>
    <item>
      <title>Re: Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155361#M7259</link>
      <description>&lt;P&gt;Yes correct Chris. On the same single (trunk) port i will configured one vlan to route over internet and one other vlan as internal network. I know this can be easily done with making 2 separate physical interfaces one (WAN) and one (LAN). But just want to confirm first if there is a way to make this setup or not? because if there is no way then i will go to the original plan to use 2 physical interfaces instead. just to note i am using SMB device 1450 on a cluster.&lt;/P&gt;&lt;P&gt;Please let me know how it goes then.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 04:17:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155361#M7259</guid>
      <dc:creator>mrknthny</dc:creator>
      <dc:date>2022-08-22T04:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155364#M7260</link>
      <description>&lt;P&gt;From my testing this isn't possible, both the Web UI and CLI block the configuration of Internet+LAN as VLANs together on a single port.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 06:29:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155364#M7260</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-22T06:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155378#M7261</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;Basing on your testing, i will conclude then that it is not possible to create a trunk on any interface of an SMB appliance to use as both Internet + LAN. I will proceed then to configure individual interfaces one on WAN and another on LAN for my requirement. I appreciate your help taking time to check on this.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 07:08:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155378#M7261</guid>
      <dc:creator>mrknthny</dc:creator>
      <dc:date>2022-08-22T07:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155406#M7267</link>
      <description>&lt;P&gt;regardless of the SMB Series, it is precisely on Gaia Embedded that the default can be inserted on the WAN interface or on a bond that contains the WAN interface.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2022 11:39:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155406#M7267</guid>
      <dc:creator>AngelettaA</dc:creator>
      <dc:date>2022-08-22T11:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155483#M7272</link>
      <description>&lt;P&gt;The problem with embedded and default route is that it can only be set on a WAN interface, but there is a simple way around it.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Set 2 routes: 0.0.0.0/1 (mask 128.0.0.0) to your nexthop and 128.0.0.0/1 to the nexthop.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Aug 2022 06:38:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/155483#M7272</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2022-08-23T06:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Route Default GW not via WAN interface but via sub-vlan interface</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/199942#M9938</link>
      <description>&lt;P&gt;Hi Maarten ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you confirm this workaround could work ?&lt;/P&gt;
&lt;P&gt;what if we use a bond with the WAN interface that will be not used ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Farid&lt;/P&gt;</description>
      <pubDate>Thu, 07 Dec 2023 09:21:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Route-Default-GW-not-via-WAN-interface-but-via-sub-vlan/m-p/199942#M9938</guid>
      <dc:creator>faridb</dc:creator>
      <dc:date>2023-12-07T09:21:19Z</dc:date>
    </item>
  </channel>
</rss>

