- CheckMates
- :
- Products
- :
- General Topics
- :
- About Checkpoint's Bridge Mode Constraints
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
About Checkpoint's Bridge Mode Constraints
Hello Team,
We're thinking of a IPS configuration for monitering IoT communication and PC communication.
If Quantum is installed between L3SW and L2Sw as an IPS, is it possible to configure it as follows?
I would like to run Quantum in bridge mode (L2), but since the URL below says "Important - Only two interfaces can be connected by one Bridge interface", I don't think it can meet the requirements in bridge mode, am I right?
If you know of any best practices or proven methods using checkpoints, please let me know.
Thank you in advance.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have to be wary of double inspecting any traffic flows, so with this in mind the only potential solution that comes to mind involves additional cabling and running the firewall as VSX to partition the segments.
Suggest engaging your local SE to help you validate possible options and engage with solution center if needed.
By contrast implementing the links to the routers via an intermediate switch helps from a plumbing perspective but creates a visibility issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In general it means a given bridge e.g. br1 is comprised of two interfaces "1A" and "1B"
To help could you please clarify your diagram some...
Is there only one subnet between the Layer-3 switch and the routers shown or is each on it's own subnet / VLAN?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for the reply.
Our environment aggregates routing to L3SW. Therefore, the router, L3SW, IOT devices and computers at the headquarters belong to the same network. Of course, branches have different networks.
The diagram is shown below.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have to be wary of double inspecting any traffic flows, so with this in mind the only potential solution that comes to mind involves additional cabling and running the firewall as VSX to partition the segments.
Suggest engaging your local SE to help you validate possible options and engage with solution center if needed.
By contrast implementing the links to the routers via an intermediate switch helps from a plumbing perspective but creates a visibility issue.
