<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to configure public address on port with /31 mask in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198146#M9788</link>
    <description>&lt;P&gt;I had seen people do this before and it did work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just tried bogus IP in the lab and it took it&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CP-STANDALONE-backup&amp;gt; set interface eth3 ipv4-address 9.10.11.19 mask-length 31&lt;BR /&gt;CP-STANDALONE-backup&amp;gt; save config&lt;/P&gt;</description>
    <pubDate>Thu, 16 Nov 2023 13:14:52 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-11-16T13:14:52Z</dc:date>
    <item>
      <title>Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198131#M9786</link>
      <description>&lt;P&gt;I am trying to configure public address with /31 mask on interface of CP 1550 (V-80) appliance.&lt;BR /&gt;Running SW is Version: R81.10.08 (996001608)&lt;BR /&gt;In command line it looks as it should be possible but at the end it is not working.&lt;BR /&gt;This is printout of commands I am using.&lt;/P&gt;&lt;P&gt;Electo&amp;gt; set interface LAN4 ipv4-address 1.2.3.255 mask-length 255.255.255.254&lt;BR /&gt;Could not set interface mask-length: Value is not a valid number&lt;BR /&gt;Could not set interface mask-length: Value is too low. The minimum value allowed is 1&lt;BR /&gt;Could not set interface mask-length: Value is too high. The maximum value allowed is 32&lt;BR /&gt;Could not set interface mask-length: Value is not a valid number&lt;BR /&gt;Could not set interface mask-length: Value is too low. The minimum value allowed is 1&lt;BR /&gt;Could not set interface mask-length: Value is too high. The maximum value allowed is 32&lt;BR /&gt;Electo&amp;gt;&lt;BR /&gt;Electo&amp;gt; set interface LAN4 ipv4-address 1.2.3.255 mask-length 31&lt;BR /&gt;Could not set interface subnet-mask: Invalid subnet mask&lt;BR /&gt;Electo&amp;gt;&lt;/P&gt;&lt;P&gt;At the end, is it possible to configure it or not?&lt;BR /&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 12:12:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198131#M9786</guid>
      <dc:creator>Siljo</dc:creator>
      <dc:date>2023-11-16T12:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198138#M9787</link>
      <description>&lt;P&gt;&lt;SPAN&gt;It should work in R80.20.30 and higher, if not please raise a support case with TAC to investigate further.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 12:44:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198138#M9787</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-16T12:44:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198146#M9788</link>
      <description>&lt;P&gt;I had seen people do this before and it did work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just tried bogus IP in the lab and it took it&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CP-STANDALONE-backup&amp;gt; set interface eth3 ipv4-address 9.10.11.19 mask-length 31&lt;BR /&gt;CP-STANDALONE-backup&amp;gt; save config&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 13:14:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198146#M9788</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-16T13:14:52Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198160#M9790</link>
      <description>&lt;P&gt;which appliance did you used?&lt;/P&gt;&lt;P&gt;I have 1550, and it is refusing to accept command.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 14:09:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198160#M9790</guid>
      <dc:creator>Siljo</dc:creator>
      <dc:date>2023-11-16T14:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198161#M9791</link>
      <description>&lt;P&gt;Looks like a full GAiA appliance.&lt;/P&gt;
&lt;P&gt;As above if it does not work for you please contact support &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 14:10:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198161#M9791</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-16T14:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198162#M9792</link>
      <description>&lt;P&gt;I used eve-ng standalone config lab. I dont sadly have any smb appliance to test, but let me spin one up quick on demo point and will check.&lt;/P&gt;
&lt;P&gt;Give me 10-15 mins.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 14:13:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198162#M9792</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-16T14:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198166#M9794</link>
      <description>&lt;P&gt;Appears to be some sort of limitation. I tried, but exact same issue. Maybe TAC case would help here, speciailly based on below thread...&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/SMB-Gateways-Spark/WAN-interface-on-1590-with-31-Subnet-Mask/td-p/116709" target="_blank"&gt;https://community.checkpoint.com/t5/SMB-Gateways-Spark/WAN-interface-on-1590-with-31-Subnet-Mask/td-p/116709&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 14:31:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198166#M9794</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-16T14:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198167#M9795</link>
      <description>&lt;P&gt;Thanks for check and quick answer.&lt;/P&gt;&lt;P&gt;It seems that next stop is TAC&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Mario&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 14:38:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198167#M9795</guid>
      <dc:creator>Siljo</dc:creator>
      <dc:date>2023-11-16T14:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198168#M9796</link>
      <description>&lt;P&gt;No worries. Yes, I would agree, thats your best bet at this point.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;P.S. I will keep trying to see if there is any way around it, but so far, just keeps saying its invalid subnet mask...if I get anywhere, will update you.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 14:43:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198168#M9796</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-16T14:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198171#M9797</link>
      <description>&lt;P&gt;Im 100% positive this has nothing to do with the version at all, as its same on few different codes. Just working on some Palo Alto stuff right now, but will get back to this soon.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 15:17:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198171#M9797</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-16T15:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198176#M9800</link>
      <description>&lt;P&gt;No luck as of yet, but here is something Im not really grasping, if you will. Maybe someone from CP can clarify...Im not subnetting expert by any means, but if you think about it logically, /31 is essentially 2 hosts, which neither one can be used, as one is network and other is broadcast IP, so in that case, how come it works on regular Gaia, but not on smb?&lt;/P&gt;
&lt;P&gt;Maybe below would explain it?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk91020" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk91020&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 17:01:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198176#M9800</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-16T17:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198188#M9802</link>
      <description>&lt;P&gt;Indeed /31 has only 2 IP addresses inside, but it is used for point to point links for small ISP-s to not waste 50% of address space.&lt;/P&gt;&lt;P&gt;Some vendors support /31 subneting, but CP on SMB-s unfortunately is not one of them.&lt;/P&gt;&lt;P&gt;Maybe in some next SW release.&lt;/P&gt;&lt;P&gt;Anyhow thanks for your help.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Mario&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 18:30:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198188#M9802</guid>
      <dc:creator>Siljo</dc:creator>
      <dc:date>2023-11-16T18:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198189#M9803</link>
      <description>&lt;P&gt;Yes, exactly.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 18:34:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198189#M9803</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-16T18:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198198#M9804</link>
      <description>&lt;P&gt;The high address in a network block is reserved for broadcast. What a lot of people seem to miss is this is also the reason the low address in a network block is reserved. Before IP broadcast was standardized in RFC 919 in late 1984, some vendors had introduced their own implementation of broadcast using the low address. It's still commonly reserved today to avoid conflicting with implementations from the 80s (like old mainframes which tend to be business-critical to big companies). Thus, a /31 network could be considered to contain two broadcast addresses. Broadcast actually means "everyone in this network except me", so two broadcast addresses could uniquely identify two hosts.&lt;/P&gt;
&lt;P&gt;RFC 3021 standardized use of 31-bit IPv4 network blocks in late 2000.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 19:32:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198198#M9804</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-11-16T19:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198199#M9805</link>
      <description>&lt;P&gt;I still dont see the logic as to why /31 works on regular Gaia and not on embedded version. Maybe someone from CP can clarify the reason, unless its internal info only...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 19:43:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198199#M9805</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-16T19:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198202#M9806</link>
      <description>&lt;P&gt;It'll be a bug in the configuration validation logic. The part which takes "set interface eth1 ipv4-address 10.20.30.40 mask-length purple" and tells you "Purple isn't a valid netmask, dummy!"&lt;/P&gt;
&lt;P&gt;The Linux network stack has supported 31-bit netmasks since somewhere in 2.5, so it's very unlikely to be something lower level. You can almost certainly use ifconfig to set the interface to a 31-bit mask by hand (ifconfig eth5 10.20.30.40 net mask 255.255.255.254), it just won't survive reboot thanks to clish.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 20:51:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198202#M9806</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-11-16T20:51:26Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198203#M9807</link>
      <description>&lt;P&gt;Agree, thats true. Anyway, would like to see if there is an official CP answer to all this : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 21:37:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198203#M9807</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-16T21:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198210#M9809</link>
      <description>&lt;P&gt;Seems like this has happened before: &lt;A href="https://community.checkpoint.com/t5/SMB-Gateways-Spark/WAN-interface-on-1590-with-31-Subnet-Mask/m-p/116709#M5105" target="_blank"&gt;https://community.checkpoint.com/t5/SMB-Gateways-Spark/WAN-interface-on-1590-with-31-Subnet-Mask/m-p/116709#M5105&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;Please consult with the TAC: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Nov 2023 22:16:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198210#M9809</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-16T22:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198386#M9821</link>
      <description>&lt;P&gt;Finally it works.&lt;/P&gt;&lt;P&gt;All the time I was trying to configure /31 on local network port.&lt;/P&gt;&lt;P&gt;This is not working, configuration is not accepted by SMB.&lt;/P&gt;&lt;P&gt;But when same port is configured as Internet connection from GUI then SMB accepts /31 network for that port.&lt;/P&gt;&lt;P&gt;Problem solved &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Anyhow many thanks for help.&lt;/P&gt;&lt;P&gt;Br&lt;/P&gt;&lt;P&gt;Mario&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 13:53:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198386#M9821</guid>
      <dc:creator>Siljo</dc:creator>
      <dc:date>2023-11-20T13:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to configure public address on port with /31 mask</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198387#M9822</link>
      <description>&lt;P&gt;Learned something new today, though I rarely work on SMB appliances, thats good to know.&lt;/P&gt;
&lt;P&gt;Thanks mate &lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 13:55:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Is-it-possible-to-configure-public-address-on-port-with-31-mask/m-p/198387#M9822</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-11-20T13:55:53Z</dc:date>
    </item>
  </channel>
</rss>

