- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Exclude all Traffic inspection on certain port/vla...
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Exclude all Traffic inspection on certain port/vlan
Hello everyone,
I plan to install SMB 1530 and I would like to exclude all traffic from a certain port or vlan. Is this possible?
I am already using SMB 750 and I couldn't find a solution for this.
You probably wonder why should someone do that? 🙂
I am evaluating some decentralized storage and there are huge numbers of simultaneus connections which are also consuming high bandwidth so I don't want to overkill my SMB 🙂
With vlans, I would like to isolate this traffic in my local network and also to protect all other traffic. 🙂
Thanks in advance.
Regards
5 Replies
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Define precisely what you mean by "exclude all traffic from a certain port."
You can certainly allow all traffic to/from a certain VLAN.
What is the precise nature of the traffic?
Also, is this SMB appliance managed locally or remotely?
You can certainly allow all traffic to/from a certain VLAN.
What is the precise nature of the traffic?
Also, is this SMB appliance managed locally or remotely?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
By exclude all traffic from a certain port or vlan I mean all traffic which goes through eth_1 (example) shouldn't be examined/filtered/whatever, so that my CheckPoint SMB won't be overloaded because as I already wrote, I will be using decentralized storage which use hundreds of simultaneus connections. Those connections are also consuming high bandwidth and by all means I am not interested in securing them.
Maybe the most precise description would be: I would like to have some DMZ service but without interfering with my local network.
My SMB 1530 would be managed locally (I don't have management server, if that's your question).
Thank you for your answer.
Regards
Maybe the most precise description would be: I would like to have some DMZ service but without interfering with my local network.
My SMB 1530 would be managed locally (I don't have management server, if that's your question).
Thank you for your answer.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Technically, it is not possible to disable ALL inspection.
The best you can do is something like the "fast acceleration" feature described here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
You can try the commands listed here, but I'm not sure they'll work on SMB appliances.
The best you can do is something like the "fast acceleration" feature described here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
You can try the commands listed here, but I'm not sure they'll work on SMB appliances.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For such a task i would add other hw switch and only connect internet traffic to the SMB.
CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You may also wish to review the following options where relevant, see also sk111756.
CCSM R77/R80/ELITE
