- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: firewall setup on 2 non-routeable networks
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
firewall setup on 2 non-routeable networks
hello all,
I am still new to Checkpoints so forgive me if this seems dumb. I have 2 private networks but want to limit and restrict more access to the second network (LAN) side and only allow access to the DC ETC... this should be fairly straight forward but I am struggling with it. the WAN side is the regular business network. I can also move the WAN connection and reconfigure LAN port 4 if its easier. thanks
_
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
also it is a 1200 r with
R77.20.81
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It would help if you state your requirements in terms of:
- What host initiates the communication (LAN or WAN side)
- What host will be the recipient of the connection (LAN or WAN side)
- What services you intend to permit
Since you mention a DC (I assume you mean Datacenter) I assume the hosts may not be on the same subnet as your WAN interface.
That suggests you will have to adjust routing so hosts on your WAN know how to reach the LAN on your gateway.
Or you need to utilize NAT.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Dameon,
here are some answers to your questions
- What host initiates the communication (LAN side )
- What host will be the recipient of the connection (LAN for some WAN for others)
- What services you intend to permit RDP/SQL/AD/WSUS server/Antivirus Will ping work?(probably not if using NAT)
thanks,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What you describe should work without any configuration whatsoever, assuming a factory default configuration.
This is because:
- LAN to WAN traffic is by default permitted
- LAN/LAN traffic is generally not filtered at all
- Traffic destined to the WAN from the LAN should be hidden behind the WAN IP
Here's what you should see in the NAT and Policy screens:
You should try to ping the relevant hosts from the gateway to ensure you're not experiencing some other sort of connectivity issue.
