IPSec VPN Tunnel & SSL VPN user capacity

Hi, I am working on an important RFP and need the following clarification on IPsec and SSL VPN - 1. How many Site-to Site VPN does CP 23500 and CP 15600 support ? 2. How many SSL VPN concurrent users does CP 23500 & CP 15600 support ? A quick ...

Gaia HealthCheck Script v6.08 released

Check Point released v6.08 of it's Gaia HealthCheck Script. Script author: @Nathan_Davieau (LinkedIn profile) Whats new: Licenses and Contracts Check Whats missing: Script self-update Support for virtual switches and ...

Gateway generating unwanted traffic to a destination server

Hello,I have the following query:Scenario:Gateway IP: X.Y.Z.QServer IP: A.B.C.D (on cloud)The server is accessed by internal users on port 8080.The gateway is also generating unwanted traffic to the destination on port 8080 which is abnormal behav...

multicast issue

Hello,we have checkpoint r8010 running on two gateways and  we have 2 different vlans  on these gateways: vlan 1 and vlan 10 . there is no access restriction between these two networks.we stream mu...

ISP redundancy Load sharing one link failure

Hi Team,I have configure ISP redundancy > load sharing in Checkpoint r80.20. I have managed to send traffic 60% and 40% from 2 ISP links. If one of the ISP link (suppose 40%) goes down, does all the traffic goes via another ISP which is ha...
HeikoAnkenbrand inside Enterprise Appliances and Gaia OS yesterday
R80.20 cheat sheet - fw monitor

Introduction This overview gives you an view of the changes in R80.20 fw monitor. All R80.10 and R80.20 changes are contained in this command overview (cheat sheet). You could download the cheat sheet at the end of this article as a PDF file...

Cluster VIP MAC address

Is there a way from the command line to find the cluster VIP MAC address?I ran "arp -a" and I don't see it in there.Thanks in advance.

R80.20 - OSPF Implementation

Looking for some clarification about R80.20's OSPF implementation.sk98226 - says that R80.20 supports RFC 2328.However, the R80.20 Admin Guide (Configuring OSPF - Gaia Portal) states that the implementation is actualy RFC 2178.Which one is correct?

Adding a third 5800 to a current 5800 Firewall Cluster

We currently have a two-firewall cluster. We are working on getting a third member added to this cluster and I have it on my desk for configuration. We are required to have most of the set up done before it is racked and added to the network. This...
HeikoAnkenbrand inside Enterprise Appliances and Gaia OS Friday
R80.x Ports Used for Communication by Various Check Point Modules

Introduction This drawing should give you an overview of the used R80 and R77 ports respectively communication flows. It should give you an overview of how different Check Point modules communicate with each other. Furthermore, services that...

Destination port NAT on gateway main IP

I did a migration earlier this week from ScreenOS to Check Point where VIP IP's were used to do an incoming port NAT to multiple DMZ servers.I have my security policy configured to allow incoming traffic to the gateway object on port 5522.The NAT ...
Danny inside Enterprise Appliances and Gaia OS Thursday
Gaia HealthCheck Script v6.05 released

Check Point released v6.05 of it's Gaia HealthCheck Script.Script author: Nathan Davieau (LinkedIn profile)Whats new:Improved SND/FW Worker Overlap Check Whats missing:script self-updateDownloadPackageLinkDate sc...

Service Routing - Interfaces used for services

Dear community,I work with Palo Alto Networks firewalls and Checkpoint.Today, I was wondering, why I'm unable to get a cpuse connections from Gaia R77.30.After a short troubleshooting I found out, that some domain servers where unreachable from ma...
inside Enterprise Appliances and Gaia OS Monday
R80.20 EA for Gateway with Linux 3.10 Kernel Coming Soon

We are about to launch an EA program for R80.20 based gateway with a new Linux kernel (3.10, or 3.10.0-862 to be precise).This will allow all those customers looking at newer Open Servers with new CPUs to actually try them out with Gaia and R80.20...

R80.30 EA - 2.6 or 3.10?

Hello,Anyone managed to try R80.30 EA?  Submitted questionnaire and applied a couple of weeks ago but haven't heard anything yet.What is the version of kernel included in R80.30 EA?R80.20 with 3.10 kernel seems to work for us (we're unfortuna...