Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
pavan_kalal
Participant
Jump to solution

Intra vlan communication

Hi all,

 

does intra vlan communication required any policy push in checkpoint ?

 

i means when two hosts are connected on same vlan but unable to communicate like telnet .

does any policy required here to allow communication. ?

 

thanks 

 

 

0 Kudos
2 Solutions

Accepted Solutions
the_rock
Legend
Legend

I agree with Chris. Usually no policy would be needed for that, since it would not be crossing the firewall, BUT, just to be 100% sure, if traffic fails, you can examine the logs, just to make sure.

Also, lets take basic example, this will prove the point without any doubt. Say host IP is 10.10.10.10, you can initiate traffic and while doing so, run tcpdump -enni any host 10.10.10.10 from expert mode and if you dont see anything, then its not even hitting the firewall at all.

Andy

View solution in original post

0 Kudos
the_rock
Legend
Legend

Hey @pavan_kalal 

I attached a file I put together for some troubleshooting steps to take in relation to generic issues. Hope it will help you.

Cheers,

Andy

View solution in original post

0 Kudos
(1)
9 Replies
Chris_Atkinson
Employee Employee
Employee

Typically no since this traffic would traverse between end devices at the switch level without firewall interaction. 

Which gateway model do you have?

CCSM R77/R80/ELITE
0 Kudos
(1)
pavan_kalal
Participant

Its 3400 series anyways it was not issue of firewall.

 

cheers!

the_rock
Legend
Legend

Good job! 👍

0 Kudos
pavan_kalal
Participant

Thanks to everyone and checkmate, for such wonderful platform where one can post his/her qeury -doubts and get instant real time solution. 

cheers.. !

 

 

the_rock
Legend
Legend

Glad we can help mate 🙏

0 Kudos
the_rock
Legend
Legend

Hey @pavan_kalal 

I attached a file I put together for some troubleshooting steps to take in relation to generic issues. Hope it will help you.

Cheers,

Andy

0 Kudos
(1)
pavan_kalal
Participant

Appreciate, thanks lot..

 

cheers..!

0 Kudos
the_rock
Legend
Legend

No problem!

0 Kudos
the_rock
Legend
Legend

I agree with Chris. Usually no policy would be needed for that, since it would not be crossing the firewall, BUT, just to be 100% sure, if traffic fails, you can examine the logs, just to make sure.

Also, lets take basic example, this will prove the point without any doubt. Say host IP is 10.10.10.10, you can initiate traffic and while doing so, run tcpdump -enni any host 10.10.10.10 from expert mode and if you dont see anything, then its not even hitting the firewall at all.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events