Deploying a Single Security Gateway or ClusterXL in Bridge Mode

Introduction to Bridge Mode

If you cannot divide the existing network into several networks with different IP addresses, you can install a Check Point Security GatewayClosed Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources. (or a ClusterXL) in the Bridge ModeClosed Security Gateway or Virtual System that works as a Layer 2 bridge device for easy deployment in an existing topology..

A Security Gateway (or ClusterXL) in Bridge Mode is invisible to Layer 3 traffic.

When traffic arrives at one of the bridge subordinate interfaces, the Security Gateway (or ClusterClosed Two or more Security Gateways that work together in a redundant configuration - High Availability, or Load Sharing. Members) inspects it and passes it to the second bridge subordinate interface.

Example Topology for a single Security Gateway in Bridge Mode




Network, which an administrator needs to divide into two Layer 2 segments.

The Security Gateway in Bridge Mode connects between these segments.


First network segment.


Switch that connects the first network segment to one bridged subordinate interface (4) on the Security Gateway in Bridge Mode.


One bridged subordinate interface (for example, eth1) on the Security Gateway in Bridge Mode.


Security Gateway in Bridge Mode.


Another bridged subordinate interface (for example, eth2) on the Security Gateway in Bridge Mode.


Dedicated GaiaClosed Check Point security operating system that combines the strengths of both SecurePlatform and IPSO operating systems. Management InterfaceClosed (1) Interface on a Gaia Security Gateway or Cluster member, through which Management Server connects to the Security Gateway or Cluster member. (2) Interface on Gaia computer, through which users connect to Gaia Portal or CLI. (for example, eth0) on the Security Gateway.


Switch that connects the second network segment to the other bridged subordinate interface (6) on the Security Gateway in Bridge Mode.


Second network segment.

For More About Bridge Mode

See the: