Hell,
Let me first start off by making it known that I am not a Network guy buy far. I am more Infrastructure but do dabble and have some skill in quite a few areas. The more you know the better, right? lol.
So here is the scenario, I have Residential internet from AT&T, 1 Dynamic IP and a set of 5 Static IPs behind that, the modem/router is in IP Passthrough mode. I recently migrated from my Palo Alto PA-3050 where this setup "Just Worked". I now have 2 Checkpoint 5800's running Gaia R80.40 in a cluster and cannot for the life of me seem to get things back the way they were.
First attempt, give each Security Gateway a dynamic Internal IP from the modem/router on the 192.168.1.X/24 network. Configure the VIP and then select Gateway 1 to forward the traffic to from the modem/router. This works and i get internet, but can only use the Public Dynamic IP, cant use any of the static IPs behind that.
Second attempt, give each Security Gateway a Public IP, assign the Cluster VIP. This does not work, i dont get internet at all.
Third attempt, forward the traffic to Gateway 1, allow it to receive the Public Dynamic IP. Cant create the Cluster VIP as not both Gateways are in the same subnet, thus no internet.
Has anyone ever successfully configure a Checkpoint cluster behind a residential AT&T router/modem? Am I doing something wrong? I am missing something? Any help or guidance is greatly appreciated.