New! R80.30 feature: Management Data Plane Separation

I really like the all new R80.30 feature for separating management from data traffic via Routing Separation and Resource Separation as described in sk138672.   Did anyone test this already?
Danny inside Enterprise Appliances and Gaia OS 6 hours ago
Gaia HealthCheck Script v6.09 released

Check Point released v6.09 of it's Gaia HealthCheck Script. Script author: @Nathan_Davieau (LinkedIn profile) Whats new: Optimized licenses and contracts check Whats missing: Script self-update Support for virtual switches...
Danny inside Enterprise Appliances and Gaia OS 6 hours ago
Gaia HealthCheck Script v6.08 released

Check Point released v6.08 of it's Gaia HealthCheck Script. Script author: @Nathan_Davieau (LinkedIn profile) Whats new: Licenses and Contracts Check Whats missing: Script self-update Support for virtual switches and ...
HeikoAnkenbrand inside Enterprise Appliances and Gaia OS yesterday
R80.20 cheat sheet - fw monitor

Introduction This overview gives you an view of the changes in R80.20 fw monitor. All R80.10 and R80.20 changes are contained in this command overview (cheat sheet). You could download the cheat sheet at the end of this article as a PDF file...

Proxy Arp's for subnet not on firewall

I have run into this several times where I create proxy arp(s) on external interface of the firewall for a distinct subnet so for example:Firewall interface arp proxy ipv4-address interface eth1 real-ipv4-addres...

how about the performance of vsec

Hi all Does anybody know what's about the performance for the vsec installed in the open server? I only find the througput of the vsec while not CPS and concurrent sessions capacity. Hope you could share your knowledge if you know them. Thanks in ...

VPN Tunnel Phase 1 Re-key Causing Application Disconnects

We have what I would call a sensitive application that is somehow losing it's connection when Phase 1 re-keys on the VPN tunnel the traffic is being tunneled through. I think it's likely a combination of gateway/tunnel settings that could be modif...

IPSec VPN Tunnel & SSL VPN user capacity

Hi, I am working on an important RFP and need the following clarification on IPsec and SSL VPN - 1. How many Site-to Site VPN does CP 23500 and CP 15600 support ? 2. How many SSL VPN concurrent users does CP 23500 & CP 15600 support ? A quick ...

R80.30 EA - 2.6 or 3.10?

Hello,Anyone managed to try R80.30 EA?  Submitted questionnaire and applied a couple of weeks ago but haven't heard anything yet.What is the version of kernel included in R80.30 EA?R80.20 with 3.10 kernel seems to work for us (we're unfortuna...

Gateway generating unwanted traffic to a destination server

Hello,I have the following query:Scenario:Gateway IP: X.Y.Z.QServer IP: A.B.C.D (on cloud)The server is accessed by internal users on port 8080.The gateway is also generating unwanted traffic to the destination on port 8080 which is abnormal behav...

multicast issue

Hello,we have checkpoint r8010 running on two gateways and  we have 2 different vlans  on these gateways: vlan 1 and vlan 10 . there is no access restriction between these two networks.we stream mu...

ISP redundancy Load sharing one link failure

Hi Team,I have configure ISP redundancy > load sharing in Checkpoint r80.20. I have managed to send traffic 60% and 40% from 2 ISP links. If one of the ISP link (suppose 40%) goes down, does all the traffic goes via another ISP which is ha...

Cluster VIP MAC address

Is there a way from the command line to find the cluster VIP MAC address?I ran "arp -a" and I don't see it in there.Thanks in advance.

R80.20 - OSPF Implementation

Looking for some clarification about R80.20's OSPF implementation.sk98226 - says that R80.20 supports RFC 2328.However, the R80.20 Admin Guide (Configuring OSPF - Gaia Portal) states that the implementation is actualy RFC 2178.Which one is correct?

Adding a third 5800 to a current 5800 Firewall Cluster

We currently have a two-firewall cluster. We are working on getting a third member added to this cluster and I have it on my desk for configuration. We are required to have most of the set up done before it is racked and added to the network. This...