- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
So i need to configure routing on my 1100 firewall and below is the information i have for the configuration-
Site subnet: 10.40.3.X/24
Eth LAN2 (vlan20 –secured): 10.40.3.21/29; dgw= 10.40.3.20/29 (int Gi0/2)
Eth LAN5 (vlan 10 - unsecured): 10.40.3.11/29, dgw = 10.40.3.10/29 (int Gi0/1)
Source network:
216.152.218.X/32
Destination networks:
Checkpoint Portal/Blade - https://10.169.90.4/sslvpn
149.122.13.X/32
149.122.13.X/32
149.122.13.X/32
So what would be the command on cli since i only have console access to configure routing?
Fo reference below is the routing configuration for another 1100 appliance and i was told that the routing should be similar to this one-
# Static routes
delete static-routes
add static-route service Any destination 10.0.0.X/8 nexthop gateway ipv4-address 10.43.1.20" metric 0
set static-route 2 service Any destination 10.0.0.X/8 nexthop gateway ipv4-address 10.43.1.20 metric 0 disabled false
add static-route service Any destination "216.152.218.X/32" nexthop gateway ipv4-address "10.43.1.X" metric "0"
set static-route 3 service Any destination "216.152.218.X/32" nexthop gateway ipv4-address "10.43.1.X" metric "0" disabled "false"
add static-route service Any destination "149.122.0.X/16" nexthop gateway ipv4-address "10.43.1.X" metric "0"
set static-route 1 service Any destination "149.122.0.X/16" nexthop gateway ipv4-address "10.43.1.X" metric "0" disabled "false"
I cannot figure out what the destination network should be as is shown for above configuration, just keeps showing error and so whenever i try out something.
maybe the destination network has to be any or something?
Can you rather draw a network plan ? I seem not to be able to figure it out from what you wrote...
so the config that you see is what i received from the telecom team, and this firewall is connected to a switch where the lan 2 port of the firewall is connected to the gi0/2 port of the switch and the lan5 pot is connected to gi0/1 of the switch as shown in the config below, i know that the writing is a bit confusing but yeah thats the info i received-
Eth LAN2 (vlan20 –secured): 10.40.3.21/29; dgw= 10.40.3.20/29 (int Gi0/2)
Eth LAN5 (vlan 10 - unsecured): 10.40.3.11/29, dgw = 10.40.3.10/29 (int Gi0/1)
All i need to configure is the routing for this firewall based on the above info, i tried the add static-route.....
command yesterday but it showed some kind of error, i will try out something today as well to see if it works or not,
so what i beleive is there should be 2 statements for the routes based on the above info. What im planning to implement today is the below commands hopefully they should work-
set static-route 1 service any destination any source 10.40.3.21/29 nexthop gateway ipv4-address 10.40.3.20 disabled false metric 0
set static-route 2 service any destination any source 10.40.3.11/29 nexthop gateway ipv4-address 10.40.3.10 disabled false metric 0
And as i mentioned for reference you can look at the routing config for the other 1100 firewall that i shared in the op which does have specific destinations by the way for the static routes.
And this part here below i implemented it as a rule in a policy-
Source network:
216.152.218.X/32
Destination networks:
Checkpoint Portal/Blade - https://10.169.90.4/sslvpn
149.122.13.X/32
149.122.13.X/32
149.122.13.X/32
So those commands that i mentioned do not work apparently, maybe there is something wrong with what i chose for the source,dest,next hop ip values.
add static-route service Any destination "149.122.13.X/32" nexthop gateway ipv4-address "X.X.X.X" metric "1"
Obviously need to replace the X with actual number required which obviously we don't have.
We won't know the next hop address on your network so cannot tell you what the X need to be
so the next hop is the dgw specified in my post
The firewall is on version R77.20 by the way.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Thu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasFri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY