CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Check Point SecurePlatform (SPLAT)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-06-24
Junior Member
 
Join Date: 2006-09-06
Posts: 2
Rep Power: 0
erwinerwinerwin has an average reputation (10+)
Default Maximum Physical Interface on CPFW

Hi all,
we're planning to use checkpoint firewall on an open-server (preferable) or any platform and probably we're gonna use up to 24 port gigabit ethernet interface, is there any suggestion regarding any server that possible to use (and preferably on checkpoint certified hardware list).

Thanks
Reply With Quote
  #2 (permalink)  
Old 2008-06-24
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,681
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Maximum Physical Interface on CPFW

I don't know of any open-server that support 24 interfaces.
The Crossbeam's will support it, but that's still a lot of interfaces for one firewall.
Reply With Quote
  #3 (permalink)  
Old 2008-07-11
Junior Member
 
Join Date: 2006-06-28
Posts: 19
Rep Power: 0
Adam Carter has an average reputation (10+)
Default Re: Maximum Physical Interface on CPFW

So you need 6 slots with quad gig eth cards. How about an HP DL580 G4/G5 (check the compatibility tho).
Check Point Software: Hardware Compatibility List -

Also check other vendors offerings in the 4-6 RU range. Boxes that size usually have plenty of slots.

But - have you thought about 802.1q trunks instead?
Reply With Quote
  #4 (permalink)  
Old 2008-07-11
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 293
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Maximum Physical Interface on CPFW

Yeah, what they said... That's a lot of physical interfaces, you should use sub-interfaces and 802.1q tags to support more networks. This is a very common setup and very easy to do in SPLAT. I'm recommending you go with a DL-380 with 3 Quad-port Intel cards, this is what I have been using for a few years now without issue.

I always use the 2 built-in ports as a single network. 1 For external and the other for HA SYNC. I divide the Intel ports up into multiple segments to keep things nice and clean.

Always remember to check the latest HCL for compliance before buying.
__________________
There's no place like 127.0.0.1

Last edited by lammbo; 2008-07-11 at 07:17.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 10:41.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0