- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Everyone,
odd question this, but I've not found a solution as yet. I have several Quantum spark appliances around the world in branch offices, connected to the main office via vpn.
I schedule periodic backups but these come out via the external (ie primary) interface address and don't decrypt and route correctly at the main office end. Is there a way to force an interface for the ftp traffic ?
Currently I send to an externally facing SFTP server, but ideally I'd come via the vpn.
Any thoughts ?
Thanks
Ian
Locally or centrally managed?
In advanced settings there is an option to source locally generated traffic from the internal address as an option.
"Use Internal IP address for encrypted communications from the local gateway"
Other options exist but may add unnecessary complexity in configuration
The procedure is different for centrally managed SMB appliances: https://support.checkpoint.com/results/sk/sk119415
Locally or centrally managed?
In advanced settings there is an option to source locally generated traffic from the internal address as an option.
"Use Internal IP address for encrypted communications from the local gateway"
Other options exist but may add unnecessary complexity in configuration
Hi Chris, this is a spark 1570 R81.10.08, and centrally managed. However the only option in advanced I can see is '
DHCP relay - Use internal IP addresses as source'
The procedure is different for centrally managed SMB appliances: https://support.checkpoint.com/results/sk/sk119415
Brilliant thank you ! Tested and works
Anyone know if this is possible on a 3000 appliance ?
I have three 3200s running R81.20 - Build 011
They are centrally managed so the setting is not available and the kernel setting does not seem available
Set operation failed: failed to get parameter fw_enc_conns_use_internal
set: Operation failed
/bin/cpfw_start: line 12: 29398 Killed $FWDIR/bin/fw "$@"
This is specific to SMB.
I don't believe it has an equivalent on regular gateway but perhaps a specific NAT rule will achieve the desired result?
Thank you, I shall try that.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY