Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Vince_Galentine
Explorer

1570R bridging

Does anyone know how to set up a bridge on the new 1570R appliances? I do not understand why it ask for an IP address on the br0 interface. If anyone can help me with how to set up the bridge (step by step) it would be greatly appreciated.   

0 Kudos
13 Replies
PhoneBoy
Admin
Admin

Don’t believe you can do a bridge without an IP address on the SMB appliances.

0 Kudos
Vince_Galentine
Explorer

OK, What address do you use? Does the bridge still work like normal? I want to run a connection through the firewall (not getting in the way of the traffic) to monitor and then maybe apply rules. Is this possible?

0 Kudos
PhoneBoy
Admin
Admin

Yes, I actually do this in my lab using Access Policy rules to block specific traffic from specific hosts on my LAN:

Screen Shot 2021-06-14 at 9.08.12 AM.png

Ideally, the IP would be on the same subnet as where you want to put the bridge, but I'm not sure it matters.

0 Kudos
Vince_Galentine
Explorer

OK thanks. Do the interfaces need to be a certain type?  Separate Network, Unassigned, LAN1 switch, or Monitor Mode? Sorry for all the questions. Working with Checkpoint since 1997 but not doing brides on SMB devices.  

0 Kudos
PhoneBoy
Admin
Admin

The interfaces you choose for the bridge (only two are supported) should be unassigned to a switch.
Monitor Mode is used when you want the device to consume data from a mirror port.

0 Kudos
Vince_Galentine
Explorer

Thank you for all the help.  

0 Kudos
Martin_Raska
Advisor
Advisor

Why there can be selected more then two ports at the same time and can be applied? Same for SMB and Gaia also.


Gateway-ID-7F7A8546> show bridge br0
name: br0
ipv4-address: 192.168.200.1
subnet-mask: 255.255.255.0
stp: on
mode: on
status:
members: DMZ
LAN1
LAN2
LAN3
LAN4

 

Doest it make any sense?

0 Kudos
PhoneBoy
Admin
Admin

Not sure why the UI allows that if it's not officially supported.
That said, it definitely works (at least on SMB).

0 Kudos
neal_culligan0
Employee
Employee

This could be the switch element on the 1570R.

We do support Interface -> LAN switch.

The CLI isn't clear if that's configured but its most likely

0 Kudos
Martin_Raska
Advisor
Advisor

Hello Neal,

its 730 appliance, all interfaces are separate L3. LAN switch was deleted.

My another questions is: Could we configure multiple bridges?

Br0 LAN1 - LAN2

Br1 LAN3 - LAN4

then use LAN5 and LAN6 as routed interface?

0 Kudos
neal_culligan0
Employee
Employee

Multiple bridges are possible, limitation is 2 interfaces per bridge.

PhoneBoy
Admin
Admin

To answer my own question why the UI allows this: A "bridge" with more than two interfaces is considered a switch.
And yes, this is definitely supported on SMB appliances (not on regular Gaia).

Martin_Raska
Advisor
Advisor

This is very good information, thanks Daemon

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events