- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hello Sirs,
I've received a requirement where the current network architecture consists of an external firewall, CoreSwitch, LAN DHCP, and various devices such as PCs, ESXi servers, and other servers. During vulnerability scanning, it was discovered that certain ports on the internal servers are potential attack targets.
To enhance security and compliance, I'm considering adding a SMB CheckPoint firewall to the network and enabling IPS functionality without disrupting the existing network architecture. I've thought about using CP's Bridge Mode for this purpose, but I have some questions.
In my proposed architecture, I plan to make ESXi and problematic servers part of the Bridge Mode setup. Would it be possible to control traffic rules using this CheckPoint firewall? For instance, can I set up rules to restrict specific IP traffic through this configuration?
such as :
Oracle Database Server Vulnerabilities (Port 0):
PCI DSS Compliance: Detected Remote Access Software (Ports 139 and 445):
Oracle Database Vulnerabilities (Port 1521):
PCI DSS Compliance: Detected Remote Access Software (Ports 21 and 22):
Unsupported Linux Kernel Version Detected (Port 23):
SSL/TLS Vulnerabilities (Ports 443 and 8081):
Does it work?
Thanks kindly support
Read here: sk101371: Bridge Mode on Gaia OS and SecurePlatform OS
Hello Sir
I just read the document, but I don't quite understand it
Regrettably I don't have physical machines in my company.
Just want to make sure, in my architecture if i want to release 2 server under to Brige mode SMB FW1600 , does that function were make same of the traditional firewall as we know, to install policy setup the rule , Source ,Destination , VPN action ?
The purpose of this is to eliminate changes to the current architecture and to control traffic and IPS functions.
Thanks your time.
Jordan
Legend:
Software Blade / 
FeatureSupported in 
Gateway mode?Supported in 
VSX mode?Firewall 

You realize you can also run a virtual security gateway inside your ESXi environment, right?
Also, it's not clear how the traffic will flow here or be restricted to going through the bridge, or might flow through the bridge more than once.
Having traffic traverse the bridge more than once is not supported (i.e. double inspection).
Hello Sir,
We have two ESXi virtual machines in our environment, and we need to implement IPS and security protection for the VMs within them. If we connect both ESXi hosts to a CheckPoint 1600 in Bridge mode, will the traffic flow be sufficient?
However , According to my CheckPoint distributor partner in Taiwan, the recommendation is to add an additional switch in this scenario. However, I don't fully understand the purpose of adding a switch without making changes to the network environment and IP settings. Additionally, I'm unsure about where this switch should be placed...:(
Ask the CP TAC engineers !
What is the physical connectivity between the ESXi server and the 1800 and how will that map to the VMs in question?
And why not run a Quantum Security Gateway as a VM instead?
Hello Sir,
That is my new writed layout as below,
If i don't want to change my current service IP address, where is the CP1600 good for this case
  
Where is the CP1600 ?
We are not deiced where is the locale of CP1600
As regarding of support team recommend
I am really confuse why we need to added a new switch between the CoreSwitch
This looks wrong, i see a loop !
How about that ?
Could you please let me know why be setting to the loop ?
Can you explain to us in detail what servers and its IP needs to be in the protected scope...like the direction of the connections?
Note that if the servers IP that's running on ESXi is in the same network segment, typically IPS would not be enforced in the first place, or can only protect a certain asset and not both at the same time.
Hello Sir,
We would like to protected these VM segment of 192.168.2.X
Are you referring to North-South traffic to different segments or, East-West traffic to protect traffic from/to servers in the same segment?
<e.g.>
192.168.2.0 <-> 192.168.2.0     : do you want security inspection to be enforced on inbound/outbound traffic between servers in the same segment?
192.168.2.0 <-> 192.168.1.0     : Or between other networks that traverses through the core switch? or both patterns?
just to make things clear.
Hello Sir,
We just to define and protect 192.168.2.X segment , Because we have going to vulnerability scan had 1433 port issue in that DB server.
So we just to confirmed Intranet traffic, actually in customer layout that have set the policy on that outside firewall.
All intranet segments can access 192.168.2.X
What about this:
:
Hello Sir,
According of your graphic your mean is that all ESXI to connected to new deploy switch DSV2 vswitch0 , 1 ?
That is my our expectations, but we afraid will the traffic be insufficient.. does it cause a loop if I keep my layout ? Vswitch0 to core switch ?
Thanks
All traffic that has to be inspected must pass thru the 1600.
we afraid will the traffic be insufficient - do you need more than 2,5 GB ?
Unfortunately , we encountered a failure after last week's testing. We have an Esxi host that, after migrating through a Vswitch, is unable to successfully obtain the Gateway. We suspect that the issue may be related to the Edge Switch, which might require a Layer 2 switch that can be configured as a trunk. It's worth noting that even though our company environment doesn't utilize VLANs for control, everything is currently operating on VLAN 1.
Even when you do not explicitly use VLANs, VLAN 1 always "exists" as it is the default LAN.
Is a Layer 2 Switch behind the firewall necessary? In CheckPoint, using Bridge mode,
 
					
				
				
			
		
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count | 
|---|---|
| 22 | |
| 17 | |
| 12 | |
| 10 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 | |
| 5 | 
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 11:00 AM (EDT)
Tips and Tricks 2025 #15: Become a Threat Exposure Management Power User!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY