- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Moving from a 4200 to a 5600, we've doubled in ethernet ports. This made me wonder, what are the pros/cons of multiple physical interfaces versus a VLAN trunk. Why would I connect, for example, VLAN1, 2, 3 and 4 to eth1, 2, 3 and 4 as opposed to trunking them all on eth1?
I could come up with this, but what am I missing?
Thanks for your response Jerry.
On our 4200's, we've just been creating trunks and dumping most of our VLANs on 1 interface.
The 5600 are going to be running in HA. 10Gb fiber is not really an option because of pricing and hardly any benefits. We won't be passing that amount of traffic through our units. Bonding 2 interfaces might be a good idea, since we have the ports available anyway.
The pro vs cons are entirley related to the specific environment.
If the environment require physically seperate networks (e.g no virtual networks (VLANs)
Generally you would see the interfaces used for seperating specific networks (External, DMZ, Internal, etc...) or for improving availability (bonding interfaces)
The use of vlans allows for cheaper physical infrastructure due to less physical kit.
This topi c did come up in the past few times and you can probably search the community for past discussions.
There are people in favor of separating physical connectivity by security zones and those who advocate trunking on the bonds.
My personal opinion is that in a cloud based environments we are relying on the trunk interfaces every time we spin-up a vSEC instance. Same goes for VSX (mostly, not always) for the external connectivity via shared switch.
If you do not have the 10G capacity, bonding 1G and trunking it is not a bad thing, IMHO. You still can have separate trunks for zones, but you'll gain the flexibility of dynamically adding more networks to your Check Point gateways programmatically, as opposed to requiring a cable runs each time for the physical interface based deployments.
There was, in the past, for a brief time a VLAN hoping exploit, but switch manufacturers have clamped down on it pretty fast and I did not hear about similar techniques succeeding recently.
Regards,
Vladimir
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY