Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
lukaszfatyga
Explorer

fwrl.conf & ipasssignment.conf

I use the fwrl.conf file to push the ttm file from MDS to the gateways. Probably, I will have to start using the ipasssignment.conf file, keeping it separate on 8 gateways will be a nightmare. I thought maybe fwrl.conf would help me keep this file centrally.

Does anyone know if this will work?

And other thing - I have 8 gateways in the community for remote access. If I need to assign a specific IP subnet to a group of users, I actually need 8 of them, for each gateway separately. It's a terrible waste of addressing.

Can it be done smarter?

0 Kudos
3 Replies
Chris_Atkinson
Employee Employee
Employee

Have you considered using Radius?

sk43857: How to configure RADIUS to assign Office Mode IP addresses

CCSM R77/R80/ELITE
0 Kudos
lukaszfatyga
Explorer

We use SAML for authentication.

If we have multiple gateways in the community, what about the routing issue then? The address assigned by RADIUS may appear on different gateways. Is there an option to advertise /32 client routes?

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Despite the name NAT Pools are one option to help simplify the routing of networks associated with specific gateways, refer:

https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_Advanced_Routing_AdminG...

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events