- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
Just looking at a scenario and asked a question around the correct "Topology" for interfaces connecting to other manufacturer firewalls. In this scenario, CP Gateway is the Internal firewall protecting the hosted Data Centres. There are links to other firewalls which provide ongoing connectivity to the varying customers networks, and links to similar with a DMZ hosting proxy services (Web, Email, etc).
My question is, should the interconnecting links be consider Internal, DMZ or External?
Cheers
Ju
External should used for interfaces that can be used to reach the Internet (i.e. it has the default route).
Which means your interface pointing towards the upper Palo (which has the Internet connected) should be marked as external.
The interface pointing towards the customer networks can be marked as a DMZ.
When making these decisions it's important to understand what these settings influence as relevant to what controls the gateway is enforcing. Provided below are some of the relevant resources for review:
SmartConsole R81.20 Help - Understanding Topology
sk108057: What does the box "Interface leads to DMZ" control in interface topology?
sk108057: How to configure the Protected Scope in Anti-Virus Settings for file downloads
sk64543: Topology and "Internet" object in Application and URL Filtering rule base
To me, logically, I would say DMZ, based on your diagram.
External should used for interfaces that can be used to reach the Internet (i.e. it has the default route).
Which means your interface pointing towards the upper Palo (which has the Internet connected) should be marked as external.
The interface pointing towards the customer networks can be marked as a DMZ.
Many thanks all for your replies, Kind Regards Ju
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY