- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
I would ask you how to resolve the below problem.
At the moment we use 6 Check Point gateways for our VPN Remote Access system.
Each gateway has dedicated Office Mode pool:
gw05 Office Mode Pool 10.76.0.0/19
gw01 Office Mode Pool 10.76.32.0/19
gw03 Office Mode Pool 10.76.64.0/19
gw06 Office Mode Pool 10.76.128.0/19
gw02 Office Mode Pool 10.76.160.0/19
gw04 Office Mode Pool 10.76.192.0/19
Despite that each pool has 8190 IP addresses it is not enough for us. We need to double each pool.
Of course we can change subnet mask to /18 but we don’t want do it. Instead of this we looking for solution where we will use two pools (each of them with subnet mask /19). When the first pool will be full IP address should be assigned from second pool
It should looks like this:
gw05 Office Mode Pool 10.76.0.0/19 and 10.77.0.0/19
gw01 Office Mode Pool 10.76.32.0/19 and 10.77.32.0/19
gw03 Office Mode Pool 10.76.64.0/19 and 10.77.64.0/19
gw06 Office Mode Pool 10.76.128.0/19 and 10.77.128.0/19
gw02 Office Mode Pool 10.76.160.0/19 and 10.77.160.0/19
gw04 Office Mode Pool 10.76.192.0/19 and 10.77.192.0/19
At the moment we use “Manual method” for Office Mode
In this method it is possible indicate only one pool / network so we decided to use ipassignment.conf file with content like this:
Because this is new configuration for us, so we decided to test it in our lab.
Of course we hadn’t possibilities to conduct that test in that scale like in production environment, so ipassignment.conf file in our lab looked like below.
The test was that 3 clients try to connect to VPN and the results was like below:
Client-1 get address 10.76.0.4
Client-2 get address 10.76.0.5
Client-3 didn’t get address (screen below)
So my questions are:
The software we used during the tests is:
Check Point R80.40 take 294 (HFA take 139)
Endpoint Security E85.40
Thanks in advance
Thats super interesting topic. Just wondering, have you actually followed below article? I would certainly confirm with TAC if this is officially supported, to use 2 subnets.
Andy
Hello Andy,
I have already gone through this article, it will not work in this case.
Thanks
Mayank
Yea, I hear you, I also went through it myself and logically, does not appear it would help. I would certainly open an official TAC case and see if they can assist you.
Using two OM IP pools on the same GW is not supported - so you would have to double the number of pool addresses instead.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY