- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Good day!
We have a checkpoint environment where we need to route traffic to our webproxy on an internal interface.
This causes a problem for the security gateway itself as the traffic towards the proxy is sent from the mgt interface and the return traffic comes back on the internal interface, hence it's getting dropped by anti spoofing.
If I route the traffic to the webproxy through the mgt interface it works for the gateways, but not for the servers which is also consuming the proxy.
When defining an interface as internal and using 'defined by routes' adding exceptions to anti spoofing seems to be greyed out.
Does anyone have a good solution on how to solve this?
Br
Jørgen
Any reason why you don't want to route it all via the internal interface? The best solution is to avoid asymmetrical routing like this, so that anti-spoofing can do its job.
Yeah that would be the best, but have not figured out how I can initiate this traffic for the gateway from the internal interface.
Please let me know!
Br
There's no special configuration required, the gateway just follows the routing table to get to where it needs to. If the route to the destination points out the Internal interface, it will use that.
Yeah right, it does. Our problem is that the return traffic will be routed directly to the mgt interface, which will cause it to be dropped by antispoofing. I dont want to route all mgt traffic via the internal interface, as long as we actually are using the dedicated mgmt interface.
In normal deployments, the mgmt interface is just another interface in the box, there's no separation of routing or whatever for management functions. If you want that, you can either redeploy it as VSX or look at Management Data Plane Separation.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY