- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hello.
We have Cluster with CheckPoint 12600(R77.30). Cluster in Hight Availabilitity mode. And we need to connect to network with subnet 10.1.1.116/30. So, one address 117 configureied to Checkpoint Cluster, other 118 to Gateway to remote network. So I was read this article https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
And then I configuried on my nodes interfaces from Network 192.168.0.116/30 and on topology configuried Cluster Interface 10.1.1.117. Then I configuried static routes like this:
10.1.1.116 masklen 30 gateway bond0.997 scopelocal;
172.16.0.1 masklen 32 gateway 10.1.1.118;
I created manual rule for internal network like this:
src: localnet dst: 172.16.0.1 - translate src: 10.1.1.116
src: localnet dst: 10.1.1.116 - translate src: 10.1.1.116
But it is not working - icmp did not answer to this hosts. In logs I can see accepted messgages and in xltsrc i can see NATed address.
How Can I find where is problem?
R77.30 is out of support since September 2019, and the 12600 has only one more month of Support left - so i wonder what you are trying to achieve here as HW/SW is very out of time...
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY