- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Experts,
I want to migrate from Cisco Router to a Checkpoint Device.
My challenge; how do i interpret the following config from Cisco Router on the Checkpoint Network Management Interface;
interface GigabitEthernet0/0
no ip address
ip flow ingress
duplex auto
speed auto
!
interface GigabitEthernet0/0.1
encapsulation dot1Q 1 native
ip address 10.10.10.1 255.255.255.0
ip flow ingress
!
interface GigabitEthernet0/0.40
description ***-VOIP***
encapsulation dot1Q 40
ip address 172.31.125.1 255.255.255.0
ip flow ingress
ip nat inside
ip virtual-reassembly in
ip policy route-map VOIPEXCH
!
interface GigabitEthernet0/0.100
description ***f-staff***
encapsulation dot1Q 100
ip address 192.168.100.1 255.255.255.0
ip flow ingress
ip nat inside
ip virtual-reassembly in
ip policy route-map LAN
!
interface GigabitEthernet0/0.101
description ***staff-2***
encapsulation dot1Q 101
ip address 192.168.101.1 255.255.255.0
ip flow ingress
ip nat inside
ip virtual-reassembly in
ip policy route-map LAN
!
interface GigabitEthernet0/0.102
description ***Guest***
encapsulation dot1Q 102
ip address 192.168.102.1 255.255.255.0
ip access-group GUEST in
ip flow ingress
ip nat inside
ip virtual-reassembly in
ip policy route-map LAN
Please how can i implement this sort of vlan on Checkpoint??
Thank you.
Hello Norbert,
Thank you for your input.
So in my case; The physical ip i assign to the interface (assume eth2) will be 10.10.10.1 (native vlan ip on the config file i posted), then i add the other vlans to eth2??
Please confirm that my assumption is correct.
Thank you for your swift response.
Best Regards.
Please had a look at the discussion here:
It is not supported having an IP configured on the native interface if tagged VLANs used on that interface.
I know, it will work but you have problems if you need support from the vendor.
And in your Cisco configuration VLAN 1 (native VLAN) is tagged with VLAN ID 1, it is not supported to have a tagged VLAN with ID 1 ( sk110096 )
As Norbert suggest, it would be the best to have VLAN 1 on another physical interface without VLAN tag, not the one with the tagged VLANs.
Wolfgang
Thank you, Norbert and Wolfgang.
I will update you once I have implemented this.
Also, I assume that i will have to create static routes on the Firewall, informing the firewall that the nexthop to those vlans is the Switch!
Kind Regards.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY