- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Does anyone know how to set up a bridge on the new 1570R appliances? I do not understand why it ask for an IP address on the br0 interface. If anyone can help me with how to set up the bridge (step by step) it would be greatly appreciated.
Don’t believe you can do a bridge without an IP address on the SMB appliances.
OK, What address do you use? Does the bridge still work like normal? I want to run a connection through the firewall (not getting in the way of the traffic) to monitor and then maybe apply rules. Is this possible?
Yes, I actually do this in my lab using Access Policy rules to block specific traffic from specific hosts on my LAN:
Ideally, the IP would be on the same subnet as where you want to put the bridge, but I'm not sure it matters.
OK thanks. Do the interfaces need to be a certain type? Separate Network, Unassigned, LAN1 switch, or Monitor Mode? Sorry for all the questions. Working with Checkpoint since 1997 but not doing brides on SMB devices.
The interfaces you choose for the bridge (only two are supported) should be unassigned to a switch.
Monitor Mode is used when you want the device to consume data from a mirror port.
Thank you for all the help.
Why there can be selected more then two ports at the same time and can be applied? Same for SMB and Gaia also.
Gateway-ID-7F7A8546> show bridge br0
name: br0
ipv4-address: 192.168.200.1
subnet-mask: 255.255.255.0
stp: on
mode: on
status:
members: DMZ
LAN1
LAN2
LAN3
LAN4
Doest it make any sense?
Not sure why the UI allows that if it's not officially supported.
That said, it definitely works (at least on SMB).
This could be the switch element on the 1570R.
We do support Interface -> LAN switch.
The CLI isn't clear if that's configured but its most likely
Hello Neal,
its 730 appliance, all interfaces are separate L3. LAN switch was deleted.
My another questions is: Could we configure multiple bridges?
Br0 LAN1 - LAN2
Br1 LAN3 - LAN4
then use LAN5 and LAN6 as routed interface?
Multiple bridges are possible, limitation is 2 interfaces per bridge.
To answer my own question why the UI allows this: A "bridge" with more than two interfaces is considered a switch.
And yes, this is definitely supported on SMB appliances (not on regular Gaia).
This is very good information, thanks Daemon
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY