- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Quantum Spark 1500 routing and traffic inspection
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Quantum Spark 1500 routing and traffic inspection
I'm trying to clarify how the 1500 devices should work by default and if this behaviour should be the same in both locally and centrally managed mode. Unfortunately I don't have one in my lab to play with and what I'm seeing on different sites appears different.
The question relates to different networks on different LAN ports. You have LAN1 as 10.10.1.254/24 and LAN2 as 10.10.2.254/24, both using the gateway as their respective default gateways.
Should traffic route between them by default without adding and additional routes or access rules, and will it be inspected? Does this differ between locally and centrally managed boxes?
The documentation suggests it should not route. If I add a static route from one network to the other then it shows as "inactive" which suggests it's not required.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Routing should work subject to the relevant policies permitting the traffic flows.
LAN to LAN traffic inspection is controlled via an advanced option for Spark appliances to help conserve resources.
Device - Advanced - Advanced Settings: Stateful Inspection - Perform deep packet inspection on LAN to LAN traffic (true|false)
See also: https://support.checkpoint.com/results/sk/sk102296
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Routing should work subject to the relevant policies permitting the traffic flows.
LAN to LAN traffic inspection is controlled via an advanced option for Spark appliances to help conserve resources.
Device - Advanced - Advanced Settings: Stateful Inspection - Perform deep packet inspection on LAN to LAN traffic (true|false)
See also: https://support.checkpoint.com/results/sk/sk102296
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You need an explicit access rule to allow the communication between LAN1 and LAN2.
As both networks are "local" no additional routing configuration should be necessary.
