- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Intervlan Routing is not working on Mgmt Interface...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Intervlan Routing is not working on Mgmt Interface for CheckPoint
Intervlan Routing is not working on Mgmt Interface for CheckPoint.
I have a New CheckPoint Firewall. On Mgmt Interface I configured L3 Sub Interfaces. In CheckPoint Mgmt Interface , need to have IP assigned , since I assigned One L3 Subnet on Mgmt Interface and created more Sub interface.
However I am not able to Ping any IP of that Subnet ( Mgmt Interface ) , from IT Network , but can Ping the Gateway from IT Network.
Also , Considering Mgmt Interface IP is 10.7.251.49 and a Server IP is 10.7.251.55 , they can Ping each other but not from IT Network. There is a OPSF between IT ( Cisco ) with CP firewall , I am redistributing the Mgmt Interface over OSPF.
CP Firewall has the route to network from where I am trying to Ping to Server IP is 10.7.251.55.
Cisco## sh run interface gigabitEthernet 3/0/48 ---- Mgmt Interface Connected
interface GigabitEthernet3/0/48
switchport trunk native vlan 2103
switchport mode trunk
Cisco##show mac address-table interface GigabitEthernet3/0/48
Mac Address Table
-------------------------------------------
Vlan Mac Address Type Ports
---- ----------- -------- -----
2103 MAC.MAC.MAC DYNAMIC Gi3/0/48
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check routing first, and then policy on your Security GW.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Anti-spoofing / asymmetric routing would be topics to start investigating here.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did not install the Smart Dashboard yet. Security GW is running on no policy using ( fw unloadlocal ) while I was preparing with single mgmt interface and install smart dashboard on that mgmt subnet.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sounds like routing or possibly incorrect netmask setting perhaps?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
From GAIA Portal is there any Anti-Spoofing Option ? I do not see any unless I missed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's defined based on the interface topology of the Gateway object in SmartConsole.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Smart Console is not setup yet just configured one LAN Interface ( mgmt ) and OSPF for WAN.
