- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Intra vlan communication
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Intra vlan communication
Hi all,
does intra vlan communication required any policy push in checkpoint ?
i means when two hosts are connected on same vlan but unable to communicate like telnet .
does any policy required here to allow communication. ?
thanks
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree with Chris. Usually no policy would be needed for that, since it would not be crossing the firewall, BUT, just to be 100% sure, if traffic fails, you can examine the logs, just to make sure.
Also, lets take basic example, this will prove the point without any doubt. Say host IP is 10.10.10.10, you can initiate traffic and while doing so, run tcpdump -enni any host 10.10.10.10 from expert mode and if you dont see anything, then its not even hitting the firewall at all.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey @pavan_kalal
I attached a file I put together for some troubleshooting steps to take in relation to generic issues. Hope it will help you.
Cheers,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Typically no since this traffic would traverse between end devices at the switch level without firewall interaction.
Which gateway model do you have?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Its 3400 series anyways it was not issue of firewall.
cheers!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Good job! 👍✔
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks to everyone and checkmate, for such wonderful platform where one can post his/her qeury -doubts and get instant real time solution.
cheers.. !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Glad we can help mate 🙏
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey @pavan_kalal
I attached a file I put together for some troubleshooting steps to take in relation to generic issues. Hope it will help you.
Cheers,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Appreciate, thanks lot..
cheers..!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No problem!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I agree with Chris. Usually no policy would be needed for that, since it would not be crossing the firewall, BUT, just to be 100% sure, if traffic fails, you can examine the logs, just to make sure.
Also, lets take basic example, this will prove the point without any doubt. Say host IP is 10.10.10.10, you can initiate traffic and while doing so, run tcpdump -enni any host 10.10.10.10 from expert mode and if you dont see anything, then its not even hitting the firewall at all.
Andy
