Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ihenock1011
Advisor

Static route in VSX

Hi Everyone,

We have a Checkpoint R81.10 security gateway in a VSX environment. I'm trying to configure the following routes:


• Source: 172.16.1.0/24
o Destination: 10.1.1.1/32
o Gateway: VPN tunnel


• Source: 172.16.1.0/24
o Destination: 0.0.0.0
o Gateway: external interface


However, the VSX route configuration seems to only allow specifying the destination IP, not the source IP. Is there a way to achieve this configuration?

 

 

 

 

0 Kudos
5 Replies
Alex-
Leader Leader
Leader

PBR requires a Virtual Router as per sk79700.

 

0 Kudos
Chris_Atkinson
Employee Employee
Employee

PBR should be possible on a VS since R80.40 per sk167135 

CCSM R77/R80/ELITE
0 Kudos
Wolfgang
Authority
Authority

No, there is no more a requirement for  a virtual router if you want to use PBR. You can use normal PBR rules.

With VSX some limitations for PBR exists.... see sk167135 - Policy-Based Routing and Application-Based Routing in Gaia mentioned by @Chris_Atkinson 

  • You can configure PBR in Gaia Clish.
  • You can configure only Source IP, Destination IP, and the Interface.
  • You cannot configure additional parameters (destination service port and protocol).
0 Kudos
Ihenock1011
Advisor

We already configure PBR as per below yet when the partner tries to reach to our endpoint it hits the external interface.

set pbr rule priority 01 match from 172.16.1.0/24
set pbr rule priority 01 match to 10.1.1.1/32
set pbr rule priority 01 action table VPN tunnel

FYI  

Partner IP: 172.16.1.0/24

Our Endpoint: 10.1.1.1/32

0 Kudos
Alex-
Leader Leader
Leader

OK, thanks for the clarification. I looked at the VSX SK, not the PBR. 😀

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events