Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
mmitic
Explorer

Exclude all Traffic inspection on certain port/vlan

Hello everyone,

I plan to install SMB 1530 and I would like to exclude all traffic from a certain port or vlan. Is this possible?

I am already using SMB 750 and I couldn't find a solution for this.

You probably wonder why should someone do that? 🙂

I am evaluating some decentralized storage and there are huge numbers of simultaneus connections which are also consuming high bandwidth so I don't want to overkill my SMB 🙂

With vlans, I would like to isolate this traffic in my local network and also to protect all other traffic. 🙂

 

Thanks in advance.

Regards 

0 Kudos
5 Replies
PhoneBoy
Admin
Admin

Define precisely what you mean by "exclude all traffic from a certain port."
You can certainly allow all traffic to/from a certain VLAN.
What is the precise nature of the traffic?
Also, is this SMB appliance managed locally or remotely?
0 Kudos
mmitic
Explorer

By exclude all traffic from a certain port or vlan I mean all traffic which goes through eth_1 (example) shouldn't be examined/filtered/whatever, so that my CheckPoint SMB won't be overloaded because as I already wrote, I will be using decentralized storage which use hundreds of simultaneus connections. Those connections are also consuming high bandwidth and by all means I am not interested in securing them.

Maybe the most precise description would be: I would like to have some DMZ service but without interfering with my local network.

My SMB 1530 would be managed locally (I don't have management server, if that's your question).

Thank you for your answer.

Regards
0 Kudos
PhoneBoy
Admin
Admin

Technically, it is not possible to disable ALL inspection.
The best you can do is something like the "fast acceleration" feature described here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
You can try the commands listed here, but I'm not sure they'll work on SMB appliances.
0 Kudos
G_W_Albrecht
Legend
Legend

For such a task i would add other hw switch and only connect internet traffic to the SMB.

0 Kudos
Chris_Atkinson
Employee
Employee

You may also wish to review the following options where relevant, see also sk111756.

dpi.png