- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Hello,
I need to configure VIP on different subnet on a SMB cluster - centrally managed - on WAN link (have not enought pub. IPs and Mgmt is directly connected).
So private IPs for the interfaces and a public IP as VIP. Problem is to set the default gateway - SMB Internet connection only allows configure Gateway in the same subnet. Adding a manual default route is also no possible.
Any idea?
sk159772 suggests this should be possible in R81.10.x
Ask TAC - https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_ClusterXL_AdminGuide/Topics-... could apply.
sk159772 suggests this should be possible in R81.10.x
| ID | Description | Found In | Resolved In |
| 01615874 | When defining a locally managed cluster, the Virtual IP address of a clustered interface has to be in the same subnet as the real IP addresses of the cluster members. | R80.20 GA | R81.10.00 |
I use centrally managed - but actually as said I heve no idea how to configure the default gateway.
Hi!
Are you trying to configure DG before or after cluster configuration?
As far as I know, DG could be configured in subnet, other than actual IP address, only when cluster configuration already done on the appliance.
Means - try to configure cluster first (with all needed IPs), install policies, and only after that - change DG on members themselves.
cluster is configured - actually the issue is in configuring the default route on gaia embedded itself!
Have you tried R81.10.05 ?
for some reason my last post was deleted with the screensot of the issue.
Did you contact TAC already ?
I pushed issue to Checkpoint SE .....will post the solution here if I get one
Hello @dede79 ,
We are facing a similar scenario, need to have member interfaces in a different subnet than virtual IP. Were you able to make it work? was default route possible?
Regards
Have you tested R81.10.07 (996001430) out of interest?
Successfully tested this to the extent my lab allows on a locally managed cluster running R81.10.07 (996001430).
Time permitting will follow-up similar tests on a centrally managed variant also.
Hi @dede79
Were you able to solve the problem with the default routes? I have the same scenario and same problem.
Could you help me? thanks
Please open a case with TAC if not already and I will follow up internally, thanks.
Share the SR number with me in private message.
Hi,
I would also like to know if there is a supported solution for centrally managed SPARK cluster with a Cluster IP Address on different subnets on the WAN interface. Could you share the solution please?
Kind Regards,
Jones
sk182234 claims that such a solution is possible for both Locally and Centrally Managed Clusters.
The feature "Single routable IP" for clusters is supported starting from the R81.10.05 release.
For Locally Managed appliances, see the R81.10.X Locally Managed Administration Guide topic "Configuring High Availability" section "Single Routable IP Cluster."
For Centrally Managed appliances, see the R81.10.X Centrally Managed Administration Guide topic "Configuring High Availability" section "Configuring a Single Routable IP Cluster in Central Management."
Example diagram:
Even if there a section in documentation about the configuration of Single Routable IP (https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Centrally_Managed/EN/Content/Topics/Co...) as described in https://community.checkpoint.com/t5/SMB-Gateways-Spark/Implementing-High-Availability-Firewall-Clust... I recently close a ticket with TAC and they say that there is no way to do this configuration with Spark Appliances in Centrally Managed mode.
I suggest to you the "local transport network" between gateway and router
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsMon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseTue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementWed 23 Sep 2026 @ 06:00 PM (EDT)
Santo Domingo: Workspace Security and SASE Live: Protección Total del Usuario Email, Endpoint y SASEAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY