I have a Checkpoint ClusterXL distributing a BGP range.
If I assign an interface to one of the IPs in that range, it will respond to ICMP (as ICMP requests are allowed in Global settings).
But since ClusterXL does not support aliases, how do I enable ping on the ENTIRE range without NAT'ing it to something behind the Checkpoint?
I thought about making ICMP request NAT rules but since it's not a TCP/UDP service, I can't use it in a NAT rule.
Proxy ARP alone doesn't seem to work either for this purpose.
I don't like the suggestion of creating a wide NAT rule to cover ALL and then excluding what I don't want in the firewall. It would get messy and confusing when I want real NATs on the same IP to actual servers behind the checkpoint in the future.
Is there another option?