I can't say I've ever had an issue like that... I had
clusters going back to the 4.1 days that used /30s for their
sync interfaces; my old home cluster (NG FP3 on IP 330s) is
running today with /30s, and has been since rebuilt a year
and a half ago (I occassionally rebuild it for giggles _
this last time was experimenting with IPSO versions later
than 3.6 on the 330). That said, I did have one customer
who did insist on /24s for their sync subnet, but could not
articulate why.
If you want an antiquated setup tested, I'd be happy to
oblige...
Michael E. Natkin (via Mobile Phone)
Security Engineer, NJ/PA
Check Point Software Technologies, Inc.
mailto://mnatkin us.checkpoint.com
Mobile:570-371-8355
This information is intended only for the person to whom it
is addressed and may contain confidential material. If you
are not the intended recipient, you are hereby notified that
any action taken upon this message is prohibited. If you
received this in error, please contact the sender and delete
the material from any computer.
-----Original Message-----
From: cisco4ng <cisco4ng YAHOO.COM>
Sent: Thursday, March 27, 2008 5:11 PM
To: FW-1-MAILINGLIST AMADEUS.US.CHECKPOINT.COM
Subject: [FW-1] Checkpoint synchronization interface ip
address assistance needed
Can someone help me with this issue?
I remembered having this conversation with both Nokia
and Checkpoint engineers when we rolled out Checkpoint
NG Feature Pack 3 on Nokia platforms. I recalled
that both engineers Checkpoint and Nokia told me
that the "SYNC" interface must have at least /28
netmask. In other words, it must have at least
255.255.255.240 netmask. For example, my sync
interface must be at least 10.0.0.0/255.255.255.240.
I recalled that the engineers told that by by ha
[The entire original message is not included]
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV amadeus.us.checkpoint.com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http:
//www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner ts.checkpoint.com
=================================================
|