Solved

Two external interfaces with UTM-1 NGX R65

Posted on 2011-02-15
1
1,216 Views
Last Modified: 2013-11-16
I have two Checkpoint UTM-1 270s running NGX R65 in a HA cluster.  I have the several VLAN interfaces on the external interface and one non-VLAN (our default route ISP).  Routing to and from the private VLANs works fine, but I have just connected a new ISP via a VLAN on the external interface.  The connection from the ISP is up and I can PING the interface and it's gateway from the appliance, but all incoming traffic, from the internet, is dropped due to 'Address spoofing'.  I have created an object for the interface and put in a rule to allow incoming ICMP traffic, but the firewall still drops it due to spoofing.

I understand why this is happening, as the checkpoint is only expecting internet traffic to come from the interface with the default route.  But, I need the new ISP connection to allow incoming traffic, as it will be NATting traffic to a web site and other services.   Since I can't add the entire Internet to the topology of the this interface, I am at a loss here.  How do I make this happen?

This interface does not need to allow internally initiated outbound traffic (but that would be nice too.)

David Griswold

0
Comment
Question by:david_griswold
1 Comment
 

Accepted Solution

by:
david_griswold earned 0 total points
ID: 34901430
Never mind.  I forgot to specify in the firewall Topology that this was an external interface.  I assumed, incorrectly, that if I associated the VLAN with the external interface when I created it, it would default to being external.  Guess not.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Port forwarding in Cisco RV215w 2 46
ASA Objects for Non Standard Ports 42 99
The endless cat and mouse game of fail2ban 4 100
ASE reports it as spam 2 123
I recently had the displeasure of buying a new firewall at one of the buildings I play Sys Admin at. I had to get a better firewall than the cheap one that I had there since I was reconnecting the main office to the satellite office via point-to-poi…
Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
Hi friends,  in this video  I'll show you how new windows 10 user can learn the using of windows 10. Thank you.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now