<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB Masters #2 - EMEA and APAC - Video and Materials in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Masters-2-EMEA-and-APAC-Video-and-Materials/m-p/180312#M8887</link>
    <description>&lt;P&gt;Hello, I believe you mention that scopelocal feature is now available on R81.10.05 for quantum spark appliances, any guidance on how to go about configuring this?&lt;/P&gt;</description>
    <pubDate>Tue, 09 May 2023 08:32:31 GMT</pubDate>
    <dc:creator>Y_A</dc:creator>
    <dc:date>2023-05-09T08:32:31Z</dc:date>
    <item>
      <title>SMB Masters #2 - EMEA and APAC - Video and Materials</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Masters-2-EMEA-and-APAC-Video-and-Materials/m-p/177244#M8689</link>
      <description>&lt;P&gt;Hi and thanks to all who joined our "&lt;SPAN&gt;SMB Masters #2 - EMEA and APAC" session today.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Here is the video recording of the session:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;div class="lia-vid-container video-embed-center"&gt;&lt;div id="lia-vid-6323937523112w960h540r36" class="lia-video-brightcove-player-container"&gt;&lt;video-js data-video-id="6323937523112" data-account="6058022097001" data-player="default" data-embed="default" class="vjs-fluid" controls="" data-application-id="" style="width: 100%; height: 100%;"&gt;&lt;/video-js&gt;&lt;/div&gt;&lt;script src="https://players.brightcove.net/6058022097001/default_default/index.min.js"&gt;&lt;/script&gt;&lt;script&gt;(function() {  var wrapper = document.getElementById('lia-vid-6323937523112w960h540r36');  var videoEl = wrapper ? wrapper.querySelector('video-js') : null;  if (videoEl) {     if (window.videojs) {       window.videojs(videoEl).ready(function() {         this.on('loadedmetadata', function() {           this.el().querySelectorAll('.vjs-load-progress div[data-start]').forEach(function(bar) {             bar.setAttribute('role', 'presentation');             bar.setAttribute('aria-hidden', 'true');           });         });       });     }  }})();&lt;/script&gt;&lt;a class="video-embed-link" href="https://community.checkpoint.com/t5/video/gallerypage/video-id/6323937523112"&gt;(view in My Videos)&lt;/a&gt;&lt;/div&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The slides we used, and also the latest SMB flyer are also attached.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Edited Q&amp;amp;A transcript is below.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;What happened in SMB Masters #1 Is there a video? &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;Yes, see: &lt;A href="https://community.checkpoint.com/t5/SMB-Gateways-Spark/Quantum-Spark-Masters-Sept-2022-Video-Slides-and-Q-amp-A/m-p/156748#M7360" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/SMB-Gateways-Spark/Quantum-Spark-Masters-Sept-2022-Video-Slides-and-Q-amp-A/m-p/156748#M7360&lt;/A&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Is this SmartAccel on the latest version of firmware?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;Hi, yes it's in the R81.10.05 firmware which can be downloaded now.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Any plans to make HTTPS Inspection and SmartAccel don't work together?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;We are investigating this for a future release.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;How does it determine Device Type in SSL inspection? What happens if Randomization is activated?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;We have a device recognition feature that know to classify devices according to MAC address and &lt;/SPAN&gt;other&amp;nbsp;characteristics.&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Is the "SSL Inspection by Device Type" feature available in Central Management?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt; Not at this time&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;HTTPS Inspection for inbound connection?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;Not supported yet&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Are we able to add custom services under SmartAccel in the future?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;....&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Will there also be SAML Authentication for Quantum Spark?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;Currently no concrete plans. Please reach out to your Check Point office if this feature is required.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;SMS authentication for VPN: What are conditions for SMS providers / is it managed by Check Point, is there special subscription?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;It is a Check Point managed service. As of R81.10.05, it is available for all countries.&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Cluster - is the passive node accessible?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;Hi Martin, yes the passive node is accessible for management purposes. Access would be via the IP address configured on the interface not the VIP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Is Identity Awareness (with Identity Collector) supported on centrally managed appliances?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;Yes&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Cluster Scope local already available in R81.10.05 ?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;Yes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;live answered&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Any roadmap for advance access policy configuration for power user? Current way of creating access policy is cumbersome where we need to travel back and forth to create group for services/objects.&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt; live answered&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Did I see SD-WAN only for Centrally Managed? Is locally managed coming soon?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;Locally managed SDWAN capabilities&amp;nbsp;is expected as part of R81.10.10.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Is IoT Protect available on Spark?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;Yes, currently only Centrally Managed. We're working on SMP and Locally Managed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;What is the maximum number of tunnels that can be configured on SD-WAN?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;&lt;SPAN&gt;live answered&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3&gt;&lt;SPAN&gt;Who should we contact to join EA for PAYG?&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P&gt;You can contact me at &lt;A href="mailto:avig@checkpoint.com" target="_blank" rel="noopener"&gt;avig@checkpoint.com&lt;/A&gt;&lt;/P&gt;
&lt;H3&gt;PaYG...no minimum user, but is there minimum duration? 1 day? week? month? year?&lt;/H3&gt;
&lt;P&gt;live answered&lt;/P&gt;
&lt;H3&gt;For two factor authentication is only available for sms and email or can we use mfa app?&lt;/H3&gt;
&lt;P&gt;We are adding support for Google Authenticator in R81.10.10.&lt;/P&gt;
&lt;H3&gt;What is FONIC?&lt;/H3&gt;
&lt;P&gt;Fail Open NIC. When there is an hardware problem, or a software freeze, or even power failure, the WAN port and LAN port will be connected (like short wired), which will keep the connectivity up.&lt;/P&gt;
&lt;H3&gt;Would like to check if the limitation on SG1800 (1x 1GbE copper/fiber WAN2 (*future) &amp;amp; 1x 1GbE Management port (*future)) has been lifted?&lt;/H3&gt;
&lt;P&gt;Second WAN limitation on the 1600/1800 is still valid. You do, however, can use the LAN ports as WAN ports using the Flexiport feature.&lt;/P&gt;
&lt;H3&gt;Please tell me the supported IPV6 Method&lt;/H3&gt;
&lt;P&gt;live answered.&lt;BR /&gt;&lt;A href="https://www.rfc-editor.org/rfc/rfc7597" target="_self"&gt;MAP-E method&lt;/A&gt; for IPv6 is on the roadmap&lt;/P&gt;
&lt;H3&gt;Does IoT include IIoT and OT devices?&lt;/H3&gt;
&lt;P&gt;The devices that would be discovered are devices that you can find in offices and enterprises.&lt;/P&gt;
&lt;H3&gt;When is R81.10.10 expected to be available?&lt;/H3&gt;
&lt;P&gt;EA is expected end of April 2023, with release expected in Q3 2023. If you're interested in participating in the EA, please contact &lt;A href="mailto:amiray@checkpoint.com" target="_blank" rel="noopener"&gt;amiray@checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Is Active/Active for cluster in roadmap?&lt;/H3&gt;
&lt;P&gt;Not currently planned.&amp;nbsp;&lt;/P&gt;
&lt;H3&gt;Any plan to use Gaia on SMB devices instead using Embedded Gaia?&lt;/H3&gt;
&lt;P&gt;Not planned at the moment. However, we are planning to unify some of the functionality differences between the two. If you have specific requests, please work with your local Check Point office.&lt;/P&gt;
&lt;H3&gt;SD-WAN supports VPN tunnels? With 3rd party peers?&lt;/H3&gt;
&lt;P&gt;Yes, but not with third parties at this time.&lt;/P&gt;
&lt;H3&gt;Any API for local managed devices on the roadmap?&lt;/H3&gt;
&lt;P&gt;Yes.&lt;/P&gt;
&lt;P&gt;live answered&lt;/P&gt;
&lt;H3&gt;SMS Managed vs SMP Managed - Spark Appliance, which supports more features?&lt;/H3&gt;
&lt;P&gt;SMS/Smart-1 cloud provides a number of options for policy configuration, Identity Awareness etc. that isn't available in SMP. However SMP provides templates and cloud based appliance backup. I don't think its as easy as one is better than the other, but more of which is most appropriate for the use case.&lt;/P&gt;
&lt;H3&gt;Do you have any future plans with Quantum Edge?&lt;/H3&gt;
&lt;P&gt;At the moment, we are not planning future Quantum Edge releases. However,&amp;nbsp; we are interested in specific use cases for it.&lt;/P&gt;
&lt;H3&gt;Is there roadmap to have Reverse Proxy for the SMB appliances?&lt;/H3&gt;
&lt;H3&gt;live answered&lt;BR /&gt;&lt;BR /&gt;Can we save Logs on Spark Entry Appliances for 6 months?&lt;/H3&gt;
&lt;P&gt;The 1800 includes 256gb SSD storage. On other models, you can add an MicroSD card (if supported).&lt;/P&gt;
&lt;H3&gt;Infinity SMP managed - is it require license per gateway on top of Security Licenses?&lt;/H3&gt;
&lt;P&gt;No.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 08:52:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Masters-2-EMEA-and-APAC-Video-and-Materials/m-p/177244#M8689</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-04-19T08:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Masters #2 - EMEA and APAC - Video and Materials</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Masters-2-EMEA-and-APAC-Video-and-Materials/m-p/180312#M8887</link>
      <description>&lt;P&gt;Hello, I believe you mention that scopelocal feature is now available on R81.10.05 for quantum spark appliances, any guidance on how to go about configuring this?&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 08:32:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Masters-2-EMEA-and-APAC-Video-and-Materials/m-p/180312#M8887</guid>
      <dc:creator>Y_A</dc:creator>
      <dc:date>2023-05-09T08:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Masters #2 - EMEA and APAC - Video and Materials</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Masters-2-EMEA-and-APAC-Video-and-Materials/m-p/180321#M8888</link>
      <description>&lt;P&gt;Configuring the Routing Table&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;&lt;STRONG&gt;Device&lt;/STRONG&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;STRONG&gt;Routing&lt;/STRONG&gt;&amp;nbsp;page shows routing tables with the routes added on your appliance.&lt;/P&gt;
&lt;P&gt;On this page:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You can add or edit routes and configure manual routing rules. You cannot edit system defined routes.&lt;/LI&gt;
&lt;LI&gt;You can specify routes for and associate IP addresses with selected VPN tunnels. To add, delete, and modify the IP addresses, use dynamic routing protocols.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;For every route:&lt;/P&gt;
&lt;TABLE&gt;
&lt;THEAD&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Table Columns&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Description&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Destination&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;The route rule applies only to traffic whose destination matches the destination IP address/network.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Source&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;IPv4 only. The route rule applies only to traffic whose source matches the source IP address/network.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Service&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;IPv4 only. The route rule applies only to traffic whose service matches the service IP protocol and ports or service group.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Next Hop&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;The&amp;nbsp;next hop gateway&amp;nbsp;for this route, with these options:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Specified IP address of the&amp;nbsp;next hop gateway.&lt;/LI&gt;
&lt;LI&gt;Specified Internet connection from the connections configured in the appliance.&lt;/LI&gt;
&lt;LI&gt;Specified VPN Tunnel Interface (VTI).&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Metric&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Determines the priority of the route. If multiple routes to the same destination exist, the route with the lowest metric is selected.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Scope Local&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Use this setting on a&amp;nbsp;&lt;STRONG&gt;Cluster Member&lt;/STRONG&gt;&amp;nbsp;when the cluster virtual IPv4 address is in a different subnet than the IPv4 address of a physical interface. Now the&amp;nbsp;&lt;STRONG&gt;Cluster&lt;/STRONG&gt;&amp;nbsp;Member&amp;nbsp;can accept static routes on the subnet of the cluster virtual IPv4 address.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Protocol&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;Type of route. Can be Static, Directly connected, BGP, OSPF, and so on.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Rank&lt;/STRONG&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;A numeric value used to determine which protocol has a higher priority (the lower the value, the higher the priority).&lt;/P&gt;
&lt;P&gt;Static routes have a constant rank of 60 (cannot be changed).&lt;/P&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Amir_Ayalon_0-1683622882788.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20833i56399E514C56C2E1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Amir_Ayalon_0-1683622882788.jpeg" alt="Amir_Ayalon_0-1683622882788.jpeg" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&amp;nbsp;- You can configure this parameter only in&amp;nbsp;Gaia&amp;nbsp;&lt;STRONG&gt;Clish&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&lt;STRONG&gt;To add a new static route (IPv4 addresses):&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;In&amp;nbsp;&lt;STRONG&gt;Device&lt;/STRONG&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;STRONG&gt;Routing&lt;/STRONG&gt;, above the&amp;nbsp;&lt;STRONG&gt;Routing Table&lt;/STRONG&gt;, click&amp;nbsp;&lt;STRONG&gt;New&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The&amp;nbsp;&lt;STRONG&gt;New Routing Rule&lt;/STRONG&gt;&amp;nbsp;window opens with this message:&lt;/P&gt;
&lt;P&gt;Traffic from&amp;nbsp;&lt;STRONG&gt;any source&lt;/STRONG&gt;&amp;nbsp;to&amp;nbsp;&lt;STRONG&gt;any destination&lt;/STRONG&gt;&amp;nbsp;that belongs to&amp;nbsp;&lt;STRONG&gt;any service&lt;/STRONG&gt;&amp;nbsp;should be routed through the&amp;nbsp;&lt;STRONG&gt;next hop&lt;/STRONG&gt;.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;next hop&lt;/STRONG&gt;&amp;nbsp;and select an option in the new window that opens:&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;IP Address&lt;/STRONG&gt;&amp;nbsp;- Enter the IP address.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Internet connection&lt;/STRONG&gt;&amp;nbsp;- Select an internet connection.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;VPN Tunnel (VTI)&lt;/STRONG&gt;&amp;nbsp;- Select the VPN Tunnel.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;OK&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;any source&lt;/STRONG&gt;&amp;nbsp;and select an option in the new window that opens:&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Any&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Specified IP address&lt;/STRONG&gt;&amp;nbsp;- Enter the&amp;nbsp;&lt;STRONG&gt;IP Address&lt;/STRONG&gt;&amp;nbsp;and&amp;nbsp;&lt;STRONG&gt;Mask&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;any destination&lt;/STRONG&gt;&amp;nbsp;and select an option in the new window that opens:&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Any&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Specified IP address&lt;/STRONG&gt;&amp;nbsp;- Enter the&amp;nbsp;&lt;STRONG&gt;IP Address&lt;/STRONG&gt;&amp;nbsp;and&amp;nbsp;&lt;STRONG&gt;Mask&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;OK&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;any service&lt;/STRONG&gt;&amp;nbsp;and select a service name or enter a service name in the search field. You can create a new service or service group.&lt;/LI&gt;
&lt;/OL&gt;
&lt;TABLE&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Amir_Ayalon_1-1683622882791.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20834i00C5F0253F6FCCB5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Amir_Ayalon_1-1683622882791.jpeg" alt="Amir_Ayalon_1-1683622882791.jpeg" /&gt;&lt;/span&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD&gt;
&lt;P&gt;&lt;STRONG&gt;Note&lt;/STRONG&gt;&amp;nbsp;- Static routes are not supported for service-based routes using VTI (VPN).&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Optional&lt;/STRONG&gt;&amp;nbsp;- Enter a comment.&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Enter a&amp;nbsp;&lt;STRONG&gt;Metric&lt;/STRONG&gt;&amp;nbsp;between 0 and 100. The default is 0.&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;To enable&amp;nbsp;&lt;STRONG&gt;Scope Local&lt;/STRONG&gt;, select the checkbox.&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Apply&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;To configure a default route:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Go to&amp;nbsp;&lt;STRONG&gt;Device&lt;/STRONG&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;STRONG&gt;Local Network&lt;/STRONG&gt;&amp;nbsp;page.&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Select an interface and click&amp;nbsp;&lt;STRONG&gt;Edit&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The&amp;nbsp;&lt;STRONG&gt;Edit&lt;/STRONG&gt;&amp;nbsp;window opens in the&amp;nbsp;&lt;STRONG&gt;Configuration&lt;/STRONG&gt;&amp;nbsp;tab.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Click the&amp;nbsp;&lt;STRONG&gt;DHCP Server options&lt;/STRONG&gt;&amp;nbsp;tab.&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;In the&amp;nbsp;&lt;STRONG&gt;Default Gateway&lt;/STRONG&gt;&amp;nbsp;section, do one of these:&lt;/LI&gt;
&lt;UL&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Use this gateway's IP address as the&amp;nbsp;default gateway&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;LI&gt;Select&amp;nbsp;&lt;STRONG&gt;Use the following IP address&lt;/STRONG&gt;&amp;nbsp;and enter an IP address.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Apply&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;To edit a default route:&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;In&amp;nbsp;&lt;STRONG&gt;Device&lt;/STRONG&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;STRONG&gt;Internet&lt;/STRONG&gt;, click the Internet connection.&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Edit&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;The&amp;nbsp;&lt;STRONG&gt;Edit Internet Connection&lt;/STRONG&gt;&amp;nbsp;window opens in the&amp;nbsp;&lt;STRONG&gt;Configuration&lt;/STRONG&gt;&amp;nbsp;tab.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Set the&amp;nbsp;&lt;STRONG&gt;Default gateway&lt;/STRONG&gt;&amp;nbsp;(next hop) to a different IP address.&lt;/LI&gt;
&lt;/OL&gt;
&lt;OL&gt;
&lt;LI&gt;Click&amp;nbsp;&lt;STRONG&gt;Apply&lt;/STRONG&gt;.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;When no default route is active, this message shows: "Note - No default route is configured. Internet connections might be down or not configured."&lt;/P&gt;
&lt;P&gt;For Internet Connection&amp;nbsp;High Availability, the default route changes automatically on failover (based on the active Internet connection).&lt;/P&gt;
&lt;P&gt;When a network interface is disabled, all routes that lead to it show as&amp;nbsp;&lt;STRONG&gt;inactive&lt;/STRONG&gt;&amp;nbsp;in the routing page. A route automatically becomes active when the interface is enabled. Traffic for an inactive route is routed based on active routing rules (usually to the default route).&lt;/P&gt;
&lt;P&gt;The edit, delete, enable, and disable options (on the&amp;nbsp;&lt;STRONG&gt;Device&lt;/STRONG&gt;&amp;nbsp;&amp;gt;&amp;nbsp;&lt;STRONG&gt;Local Network&lt;/STRONG&gt;&amp;nbsp;page) are only available for manually defined routing rules created on this page. You cannot edit, delete, enable, and disable routing rules created by the&amp;nbsp;operating system&amp;nbsp;for directly attached networks or rules defined by the dynamic routing protocol.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To edit an existing route:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Select the route and click&amp;nbsp;&lt;STRONG&gt;Edit&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To delete an existing route:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Select the route and click&amp;nbsp;&lt;STRONG&gt;Delete&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To enable or disable an existing route:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Select the route and click&amp;nbsp;&lt;STRONG&gt;Enable&lt;/STRONG&gt;&amp;nbsp;or&amp;nbsp;&lt;STRONG&gt;Disable&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 09:02:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Masters-2-EMEA-and-APAC-Video-and-Materials/m-p/180321#M8888</guid>
      <dc:creator>Amir_Ayalon</dc:creator>
      <dc:date>2023-05-09T09:02:07Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Masters #2 - EMEA and APAC - Video and Materials</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Masters-2-EMEA-and-APAC-Video-and-Materials/m-p/180325#M8889</link>
      <description>&lt;P&gt;Thank you very much! We will try this.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 09:09:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Masters-2-EMEA-and-APAC-Video-and-Materials/m-p/180325#M8889</guid>
      <dc:creator>Y_A</dc:creator>
      <dc:date>2023-05-09T09:09:26Z</dc:date>
    </item>
  </channel>
</rss>

