CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Crossbeam
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-10-20
Junior Member
 
Join Date: 2008-10-19
Posts: 3
Rep Power: 0
jim_8912 has an average reputation (10+)
Default DMZ Design

I have recently inherited a DMZ which needs some redundancy. I am new to checkpoint and would like some input if you are willing.
From the image attached I would like to stack 3750’s and split all connections over the stack for dual connectivity e.g. Web servers, ftp etc.
(If you have any design improvements please advise) pending cost and time.

-One question I have is how would the Crossbeams handle having two active NIC’s.
-How would the ARP tables go for forwarding traffic in the event of a fail over? I am hoping to change the ARP time out?
- While typing this I thought what if the 3750's were stacked and standalone instead?
That is all I have for now but I hope the thread will be alive for some time.

jim_8912

Last edited by jim_8912; 2008-10-23 at 22:44.
Reply With Quote
  #2 (permalink)  
Old 2008-10-22
Senior Member
 
Join Date: 2006-01-25
Posts: 1,004
Rep Power: 4
melipla has an average reputation (10+)
Default Re: DMZ Design

Stack the 3750's. Then get nics that support bonding, that way you can have a single IP represented on two nics, plus additional bandwidth for the host.

HTH
__________________
Its all in the documentation.
Reply With Quote
  #3 (permalink)  
Old 2008-10-22
Junior Member
 
Join Date: 2008-10-19
Posts: 3
Rep Power: 0
jim_8912 has an average reputation (10+)
Default Re: DMZ Design

Thanks for the post.

How will the Crossbeam cluster (active/passive) cope with the new MAC add on the second switch of the stack? My attempt to make the failover seamless is one of my biggest concern.

I can play with ARP timeouts?
Reply With Quote
  #4 (permalink)  
Old 2008-10-23
Member
 
Join Date: 2007-01-12
Location: Switzerland
Posts: 44
Rep Power: 0
Dominik Zanolari has an average reputation (10+)
Default Re: DMZ Design

Hi Jim

Running VRRP should take care of your concern: Use a virtual IP address as gateway (which has it's own virtual MAC address, which is active on both firewalls). So when one gateway fails, the second one just takes over. As for ARP: The virtual IP will be associated with a virtual MAC address, but when sending traffic, the firewalls will use their burned-in MAC address, thus the virtual MAC will never appear in the switches MAC address table and traffic is flooded on all ports in the according VLAN. If your VLAN is rather big, and you are concerned about the large amount of so-called unicast flooding, you might want to limit this to the ports connecting to the firewalls: Add "switchport block unicast" on ports _not_ connecting to the firewalls and other clustered devices.

If you use state sync on the Check Point side, traffic flows are usually not affected from a failover; the short interrupt (around 1 sec) will be handled by the protocol. Best is (as always) to test this in a maintenance window... alter the VRRP prio of one box and see if connectivity still works. Would recommend to test failover with all the redundant components in your DMZ, just in case ;)

Last edited by Dominik Zanolari; 2008-10-23 at 02:34.
Reply With Quote
  #5 (permalink)  
Old 2008-11-04
Junior Member
 
Join Date: 2008-10-19
Posts: 3
Rep Power: 0
jim_8912 has an average reputation (10+)
Default Re: DMZ Design

Thanks for the ideas.

Appreciated.

JIM
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 02:02.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0