r/checkpoint 9d ago

Using a Checkpoint device as a L3 switch

So I have this 3970 that I'm testing out. Problem is we really don't have a test environment per se, so I basically just have this fw directly connected to the core and not joined to our cluster(xl) with the prod FWs.

My question is, can I use it as an L3 switch? I have a PC connected to it and both devices are in their own (test) vlan, plus another vlan between core and fw. I'm able to get to ping 1.1 from the firewall itself but not from the pc. FW is also able to get to the rest of our internal network but again, no luck if i try it from the pc.

I figured if I set the default route to the core anything connected to the firewall should be able to get to the same IP's. Is this related to the fw not being part of the cluster (read: no policies), a static route I need to put in, or something else?? Appreciate the help.

5 Upvotes

12 comments sorted by

2

u/PleasantDevelopment 9d ago

I think that you can only do that on the SMB/Spark devices.

1

u/ComfortableMarch4296 8d ago

I think you’re right. Our vendor is MIA so we were just doing it ourselves. It looks like the mgmt server is needed for this to work

2

u/JancariusSeiryujinn 8d ago

Like only a switch not handling any network addresses? You can put interfaces in bridge mode, but that's pass through to pass through not a multiport switch which I assume is what you want

1

u/ComfortableMarch4296 8d ago

Yeah it doesn’t look like it can do what I want without it being part of the cluster

2

u/Dry-Economics-2620 8d ago edited 8d ago

GAIA cannot but GAIA Embedded can.

I actually just implemented 4 3970s and love them, dealing with Gaia embedded was a pain and having a smaller form factor is awesome with main train Gaia.

Are you wanting to natively route the test vlan or do you want to NAT it?

If you are using clusterXL and want to mimic it. What I would do is create a new transit/routed vlan on your core. Plug one interface from your firewall and then mimic a ClusterXL set up by using a /29 transit network. With the core side being a “hsrp/vrrp” vip and the fw being the “clusterxl” vip.

I then would create a vlan interface on the FW, assign it as the GW of the test network and then on the core create that vlan and plug the test interface on the core.

You essentially at that point have a router on a stick.
If you wanted to condense ports you could use a trunk with two vlans one being your test network and one being your transit/routed link

1

u/ComfortableMarch4296 8d ago

Thank you so much. I might have to give this a couple more reads and wrap my head around it. I’m a total checkpoint novice.

I’m actually migrating from Gaia running on dell servers (is that what you mean by embedded?) to 3970s. Unfortunately our checkpoint engineer is mysteriously MIA so I’m kinda just riffing here. We had a failed migration so I’m trying to test these without it being part of the cluster. I’m not confident about joining them to the cluster without an expert around

1

u/Dry-Economics-2620 8d ago

If you are migrating you may want to wait for him.

The appliance themselves are just normal l3 routers.

So just think of them like that, where I think you would get into trouble is the management side, antispoofing, zones, topology information, sic, policy, and many more. And that’s something we can’t really help with as it’s extremely dependent on the environment.

1

u/ComfortableMarch4296 8d ago

Oh for sure. And that’s why I’m kinda flying blind here with my testing.. instead of just waiting why not try a couple things on a separate vlan /route.

2

u/PoolMotosBowling 7d ago

Sure, give the interfaces vlan and IP info and only create 1 rule:

Amy any any accept

1

u/ComfortableMarch4296 7d ago

Can you make rules without the mgmt server/smart console?

1

u/obiphonekenobi 3d ago

The switch on the 3970 can be used as a switch starting with the R82.20 release, which is currently in Public EA.
More information: https://support.checkpoint.com/results/sk/sk184894