Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jesussantiago01
Explorer

BGP sessions under the same VLAN

Currently, a Checkpoint firewall is being managed in which I have a VLAN to Azure. Currently, I want the Checkpoint gateway devices to receive two BGP sessions under the same VLAN ID. Would this be possible? Thank you for your help.

0 Kudos
5 Replies
Chris_Atkinson
Employee Employee
Employee

For peers on different subnets correct, is this a cluster?

Other scenarios where this has been achieved VLAN mapping or VLAN translation is used on the intermediate switch.

CCSM R77/R80/ELITE
0 Kudos
jesussantiago01
Explorer

Yes, that is correct. Both BGP peers are on different /30 subnets, but they are delivered over the same VLAN ID by Azure ExpressRoute.

And yes, this is a Check Point cluster (ClusterXL in HA mode). The challenge is that Azure provides two separate /30 peerings on a single VLAN, while Check Point does not seem to support configuring multiple IP networks on the same VLAN interface in a cluster.

Can you please confirm if there is any supported method on Check Point to handle this scenario, or if the only option is to implement VLAN mapping/translation on the intermediate switch to separate each /30 into different VLANs before reaching the firewalls?

0 Kudos
PhoneBoy
Admin
Admin

This is a long-standing limitation of ClusterXL: https://support.checkpoint.com/results/sk/sk31821
Which means you'll have to translate the VLANs somehow.

0 Kudos
soc_fenix
Explorer

Currently, a Checkpoint firewall is being managed in which I have a VLAN to Azure. Currently, I want the Checkpoint gateway devices to receive two BGP sessions under the same VLAN ID. Would this be possible?

Thank you for your help.

0 Kudos
Chris_Atkinson
Employee Employee
Employee

I have merged your thread with this existing one.

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events