Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
lphilp01
Participant

Moving to use VLANs

 

Checkpoint R82 Jumbo Hotfix Take 122 - 3600 appliance - stand alone not clustered.

I want to reconfigure my LAN to use VLANs.

Currently there is an interface; eth5 with an IP address assigned, 192.168.200.254/24. 

On the gateway, I remove the IP. I create the first VLAN and give a number; 200 and add the Original IP of the interface, save config.  Pop into Smart Console pull down the interfaces with topology and apply policy. All successful.

VLAN 1 and VLAN 200 exist on the internal switch and the connected port is a trunk with access to both VLANs.

Interface eth5,200 now exists with 192.168.200.254/24 assigned.

Routing shows a route, and the route is now linked to the VLAN interface.  

Policy allows traffic to and from the 192.168.200/24 subnet.

Yet I can't connect to anything aside from the FW Gateway in that subnet!

 

Can anyone tell me where I am going wrong please?

0 Kudos
5 Replies
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Are you seeing allow/accept logs, possibly an ARP cache/timeout or other L2 issue?

What type of switches is the VLAN tagged or untagged?

CCSM R77/R80/ELITE
0 Kudos
lphilp01
Participant

HP Instant On 1930 switches

VLAN 1 untagged default to all ports

VLAN 200 tagged all ports

Switch port to FW LAN interface is set as trunk

Nothing seen in logs for my tests at all - I tried ping and https connections to a couple of systems

 

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

What do you see with a packet capture?

CCSM R77/R80/ELITE
0 Kudos
Shyyyy
Explorer

Few things I would check, I am assuming you're trying to connect from same network subnet in the same vlan.
1. Make sure Default gateway/Subnet mask are correctly configured.
2. Run "fw ctl zdebug + drop" when trying to run traffic see if anything being dropped. (if not the same network could be Anti Spoofing).
3. if you don't see any drop running the command above it could be a layer 2 issue.

0 Kudos
Ben_Dunkley
Collaborator

I just want to make sure I'm understanding you correctly first!

Initially, there's a physical interface (eth5), connected to a switchport, the switchport is configured as a trunk port with VLAN1 untagged/native, and VLAN200 tagged, and an IP on the gateway physical interface.

Then the gateway interface is reconfigured so that it is using VLAN200, as eth5.200.

 

Is everything else that you're trying to communicate with on VLAN1 or VLAN200?

Is VLAN1 using a different subnet? (Or is your intent to just lift-and-shift VLAN1 to VLAN200?)

What device is providing inter-VLAN routing between VLAN1 and VLAN200?

You've said that you can't connect to anything else in that subnet apart from the gateway, what are you using to connect to the gateway and how? What other devices exist on the network, and how are they connected? (i.e. by which switch/switchport, and how is that port configured, etc).

Lots of questions I'm afraid!

 

I hesitate to suggest this, but my initial suspicion is that you've moved the 192.168.200.254/24 interface from VLAN1 to VLAN200, and everything else in 192.168.200.0/24 is still in VLAN1, hence the firewall can't see it at all...

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events