- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
I would ask you how to resolve the below problem.
At the moment we use 6 Check Point gateways for our VPN Remote Access system.
Each gateway has dedicated Office Mode pool:
gw05 Office Mode Pool 10.76.0.0/19
gw01 Office Mode Pool 10.76.32.0/19
gw03 Office Mode Pool 10.76.64.0/19
gw06 Office Mode Pool 10.76.128.0/19
gw02 Office Mode Pool 10.76.160.0/19
gw04 Office Mode Pool 10.76.192.0/19
Despite that each pool has 8190 IP addresses it is not enough for us. We need to double each pool.
Of course we can change subnet mask to /18 but we don’t want do it. Instead of this we looking for solution where we will use two pools (each of them with subnet mask /19). When the first pool will be full IP address should be assigned from second pool
It should looks like this:
gw05 Office Mode Pool 10.76.0.0/19 and 10.77.0.0/19
gw01 Office Mode Pool 10.76.32.0/19 and 10.77.32.0/19
gw03 Office Mode Pool 10.76.64.0/19 and 10.77.64.0/19
gw06 Office Mode Pool 10.76.128.0/19 and 10.77.128.0/19
gw02 Office Mode Pool 10.76.160.0/19 and 10.77.160.0/19
gw04 Office Mode Pool 10.76.192.0/19 and 10.77.192.0/19
At the moment we use “Manual method” for Office Mode
In this method it is possible indicate only one pool / network so we decided to use ipassignment.conf file with content like this:
Because this is new configuration for us, so we decided to test it in our lab.
Of course we hadn’t possibilities to conduct that test in that scale like in production environment, so ipassignment.conf file in our lab looked like below.
The test was that 3 clients try to connect to VPN and the results was like below:
Client-1 get address 10.76.0.4
Client-2 get address 10.76.0.5
Client-3 didn’t get address (screen below)
So my questions are:
The software we used during the tests is:
Check Point R80.40 take 294 (HFA take 139)
Endpoint Security E85.40
Thanks in advance
Thats super interesting topic. Just wondering, have you actually followed below article? I would certainly confirm with TAC if this is officially supported, to use 2 subnets.
Andy
Hello Andy,
I have already gone through this article, it will not work in this case.
Thanks
Mayank
Yea, I hear you, I also went through it myself and logically, does not appear it would help. I would certainly open an official TAC case and see if they can assist you.
Using two OM IP pools on the same GW is not supported - so you would have to double the number of pool addresses instead.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY