CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-05-23
Junior Member
 
Join Date: 2008-01-16
Posts: 10
Rep Power: 0
NACCIS has an average reputation (10+)
Default NIC Teaming on SPLAT

Peoples

I would like to know if it is possible to team 2 nics on a HP DL 360 G5. the OS is SPLAT running Provider1 (R65). I want to be to able to make my system fully redundant. As have two nics teamed feed to two different switches using the same IP.

Any idea's ?

NACCIS
Reply With Quote
  #2 (permalink)  
Old 2008-05-23
Senior Member
 
Join Date: 2006-09-26
Posts: 856
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: NIC Teaming on SPLAT

I've heard that NIC teaming is supported on NGx R65 but for firewall only,
NOT provider-1 or SmartCenter. Checkpoint wants you to buy an HA
license for a secondary Provider-1. That's how they make money.
Reply With Quote
  #3 (permalink)  
Old 2008-05-23
Junior Member
 
Join Date: 2008-04-29
Posts: 12
Rep Power: 0
ccie16798 has an average reputation (10+)
Default Re: NIC Teaming on SPLAT

hello

as far as i know it supported on *any* splat install;
sysconfig > network config > add interface > bonding
interface bonding has been around in linux for YEARS, but when a closed-source company uses a fairly outdated kernel.....

regards
Etienne



Quote:
Originally Posted by cciesec2006 View Post
I've heard that NIC teaming is supported on NGx R65 but for firewall only,
NOT provider-1 or SmartCenter. Checkpoint wants you to buy an HA
license for a secondary Provider-1. That's how they make money.
Reply With Quote
  #4 (permalink)  
Old 2008-05-23
Senior Member
 
Join Date: 2006-09-26
Posts: 856
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: NIC Teaming on SPLAT

are you sure about this? This is taken from NGx R65 2.4 kernel enforcement
module:

Choose a connection type to add ('e' to exit):
------------------------------------------------------------------
1) Secondary IP on interface (alias) 5) Loopback connection
2) VLAN 6) PPPoE connection
3) Bridge 7) PPTP connection
4) Bond 8) ISDN connection
------------------------------------------------------------------
(Note: configuration changes are automatically saved)
Your choice:

This is taken from a Provider-1 NGx R65 2.4 kernel:

Choose a connection type to add ('e' to exit):
------------------------------------------------------------------
1) Secondary IP on interface (alias) 4) PPPoE connection
2) VLAN 5) PPTP connection
3) Loopback connection 6) ISDN connection
------------------------------------------------------------------
(Note: configuration changes are automatically saved)
Your choice:

No bonding on the Provider-1 machine.
Reply With Quote
  #5 (permalink)  
Old 2008-05-26
Junior Member
 
Join Date: 2008-01-16
Posts: 10
Rep Power: 0
NACCIS has an average reputation (10+)
Default Re: NIC Teaming on SPLAT

To all
Thank you for your input. I will investigate more. But i think i may have mislead some of you. My P1's are already in HA. But my site 2 is in a full redundant state. All i need to do is team the nics on the provider 1b (ha) so that its ip is visible on both switches. Then should there be a power fail, at th switch, at the fw. I will still be able to get to the p1b(ha).

I have an idea and i will post the solution later... with some luck

NACCIS
Reply With Quote
  #6 (permalink)  
Old 2008-05-27
Junior Member
 
Join Date: 2008-04-29
Posts: 12
Rep Power: 0
ccie16798 has an average reputation (10+)
Default Re: NIC Teaming on SPLAT

Hello,

i have it too, on linux SPLAT 2.4.... strange! and i can configure bridge too...
Etienne

Choose a connection type to add ('e' to exit):
------------------------------------------------------------------
1) Secondary IP on interface (alias) 5) Loopback connection
2) VLAN 6) PPPoE connection
3) Bridge 7) PPTP connection
4) Bond 8) ISDN connection
------------------------------------------------------------------
(Note: configuration changes are automatically saved)
Your choice:
[Expert@p1-test]# uname -a
Linux p1-test 2.4.21-21cp #1 Sun Feb 11 15:56:58 IST 2007 i686 i686 i386 GNU/Linux
[Expert@p1-test]# fwm mds ver
This is Check Point Provider-1 Server NGX (R65) - Build 292
[Expert@p1-test]#







Quote:
Originally Posted by cciesec2006 View Post
are you sure about this? This is taken from NGx R65 2.4 kernel enforcement
module:

Choose a connection type to add ('e' to exit):
------------------------------------------------------------------
1) Secondary IP on interface (alias) 5) Loopback connection
2) VLAN 6) PPPoE connection
3) Bridge 7) PPTP connection
4) Bond 8) ISDN connection
------------------------------------------------------------------
(Note: configuration changes are automatically saved)
Your choice:

This is taken from a Provider-1 NGx R65 2.4 kernel:

Choose a connection type to add ('e' to exit):
------------------------------------------------------------------
1) Secondary IP on interface (alias) 4) PPPoE connection
2) VLAN 5) PPTP connection
3) Loopback connection 6) ISDN connection
------------------------------------------------------------------
(Note: configuration changes are automatically saved)
Your choice:

No bonding on the Provider-1 machine.
Reply With Quote
  #7 (permalink)  
Old 1 Day Ago
Junior Member
 
Join Date: 2007-07-03
Posts: 18
Rep Power: 0
Jay_D has an average reputation (10+)
Default Re: NIC Teaming on SPLAT

What have been the results?
I also intend to use bonding on the WAN and on the LAN interface. My intention is to connect both sides to 2 different HP switches. The switches will be connected to eachother so I suppose STP should be enabled.
I'll be using a DL380 G5 as SPLAT.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 11:36.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0