- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Dear Team ,
we have requirement like below please confirm and let us know if any limitation with this .
We have Two Chcekpoint Devices which is 5100 Series device and Cisco L2 switch for WAN and Cisco 9500 for Core Switch
Presently Both Checkpoint In One location - in proposed solution each checkpoint we be at each building .
2 Dedicated switch for ISP Connectivity at each Building
Go through Diagram it wil give your better visibility (yellow wil be fiber)
Both Location connectivity we will do over Fiber cable
Find attached Diagram Which we have created .
I have doubt about compatibility with Checkpoint and Cisco -- HSRP --- is it possible in this scenario or we should run VRRP - and what changes required and what precautions we need to take .
Your suggestion will be very important for me to run this environment with smooth way
Thanks in advance
Should not be an issue.
is there any limitation in this scenario?
If you want to run 2 ISP and as am guessing its the ISP CPE and not your own boxes.
Then you would need to run linknetworks with BGP between your check point boxes and the ISP CPE.
You would also need your own AS number and PI addresses.
I would recommend to use one /29 linknetwork for each provider so you can add both your check point boxes and use cluster xl.
Then you would route your PI addresses instead so you dont need to mess with local.arp and such things.
The inside with HSRP/VRRP dosn´t matter both will work.
With Cisco 9500 most ppl i guess would run stackwise virtual, issue with that is that is that you requires alot of fiber between your buildings.
Same as your suggested design alot of fibers are needed,
Personally i would build it like this, more or less to save fiber between the buildings if you need to add more unitis suchs as WLC, ISE servers etc.
This way you also dont need to have STP within the network.
Regards,
Magnus
Thank you for your reply -- really appreciate your help
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY