- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Does anyone know how to set up a bridge on the new 1570R appliances? I do not understand why it ask for an IP address on the br0 interface. If anyone can help me with how to set up the bridge (step by step) it would be greatly appreciated.
Don’t believe you can do a bridge without an IP address on the SMB appliances.
OK, What address do you use? Does the bridge still work like normal? I want to run a connection through the firewall (not getting in the way of the traffic) to monitor and then maybe apply rules. Is this possible?
Yes, I actually do this in my lab using Access Policy rules to block specific traffic from specific hosts on my LAN:
Ideally, the IP would be on the same subnet as where you want to put the bridge, but I'm not sure it matters.
OK thanks. Do the interfaces need to be a certain type? Separate Network, Unassigned, LAN1 switch, or Monitor Mode? Sorry for all the questions. Working with Checkpoint since 1997 but not doing brides on SMB devices.
The interfaces you choose for the bridge (only two are supported) should be unassigned to a switch.
Monitor Mode is used when you want the device to consume data from a mirror port.
Thank you for all the help.
Why there can be selected more then two ports at the same time and can be applied? Same for SMB and Gaia also.
Gateway-ID-7F7A8546> show bridge br0
name: br0
ipv4-address: 192.168.200.1
subnet-mask: 255.255.255.0
stp: on
mode: on
status:
members: DMZ
LAN1
LAN2
LAN3
LAN4
Doest it make any sense?
Not sure why the UI allows that if it's not officially supported.
That said, it definitely works (at least on SMB).
This could be the switch element on the 1570R.
We do support Interface -> LAN switch.
The CLI isn't clear if that's configured but its most likely
Hello Neal,
its 730 appliance, all interfaces are separate L3. LAN switch was deleted.
My another questions is: Could we configure multiple bridges?
Br0 LAN1 - LAN2
Br1 LAN3 - LAN4
then use LAN5 and LAN6 as routed interface?
Multiple bridges are possible, limitation is 2 interfaces per bridge.
To answer my own question why the UI allows this: A "bridge" with more than two interfaces is considered a switch.
And yes, this is definitely supported on SMB appliances (not on regular Gaia).
This is very good information, thanks Daemon
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY