- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: SMB bridge problem
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SMB bridge problem
Hi Colleagues.
Help to understand what could be the problem?
So there is a device SMB 1100
Version: R77.20.80 (990172392)
The device is controlled centrally with SMS R81 GAIA.
On the device configured Bridge for two interfaces
LAN8 and DMZ.
LAN8 -> Windows PC
DMZ -> INT LAN GW R81 GAIA -> Internet.
Traffic walks perfectly through this Bridge, but does not work Application @ Url Filtering and HTTPS inspection.
There are no entries in logs on these two blades.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Per sk111756 / sk102296 how are the following advanced settings currently configured?
Note 1100 & R77.20.80 will be End of Support in Jun-2022 and you should consider upgrading for relevant feature enhancements such as sk123035 amongst others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For sk102296
I turned on for dpi_lan_lan and dpi_lan_dmz
True
(the problem is not solved)
For sk111756
I did not find parameter Allow LAN-LAN DPI.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The sk102296 is for centrally managed SMBs like you have - Additional Settings from sk111756 do not apply here, only for locally managed SMBs! Did you do a policy install and are the new values viewable in DBedit ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would suggest to contact TAC - this did work in newer firmware versions as expected ! But i do not see why you are not using the WAN IF...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
OK, thanks, I will try to make SR in TAC.
WAN is used to connect SMB to SMS.
And Bridge is needed to connect users to another gateway with internet access and VPN (not Check Point).
Unfortunately, the scheme is not yet able to change.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
WAN is used to connect SMB to SMS. Sorry, but 🤣...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
🤷
SMS is in another region.
SMB is located in the branch office.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I thought that WAN is connected to an ISP not directly to the SMS 8) That should work, so TAC is my only hope !
