CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    R70 CCSA Courses Starting (2010) 6/7, 7/12, 8/9, 10/11, 11/8, 12/6.  R70 CCSE Courses Starting (2010) 8/16.
2. CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn and Facebook.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Dynamic Routing
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 2009-07-13
Junior Member
 
Join Date: 2005-11-08
Posts: 7
Rep Power: 0
ecorreale has an average reputation (10+)
Send a message via AIM to ecorreale
Default Failover VPN between sites

I have been searching for a solution for this everywhere without any luck. I'm hoping someone can point me in the right direction.

I have 2 NGX R65 Nokia based CheckPoint firewalls located at the main site and an R65 FW at each of 2 remote sites. I have VPN tunnels from each firewall at the central site to each of the remote sites.

Each firewall at the main site is connected externally to a unique Internet provider. Internally, they connect to the same core network.

At the moment, each internal connection exists on it's own VLAN but it doesn't have to stay that way if there is a better way of doing things.

I've included a diagram for clarity.

Problem: I want to enable vpn tunnel redundancy from the main site to each of the remote sites.

e.g.
If the Internet connection for FW-1 (not the firewall itself) fails, I need the network to realize this and start sending data over VPN tunnels connected to FW-2. I have been unable to get the internal network to realize that it needs to send via FW-2 AND switch back when the primary Internet link comes back online.

I've tried a couple of things but the same problem keeps cropping up... In my scenario, the firewall interfaces never go down, they just loose their ability to send data because of an issue with the ISP. Adding a secondary default route in the switch core doesn't work because it the core never realizes that the route is down because the interface to the firewall is always up.
Attached Thumbnails
Failover VPN between sites-vpn_diagram.jpg  
Reply With Quote
  #2 (permalink)  
Old 2009-07-15
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 876
Rep Power: 5
lammbo has an average reputation (10+)
Default Re: Failover VPN between sites

Rather than maintain 2 firewalls on 2 circuits I think you need to reconsider your architecture. I am not very well versed in the subject of ISP redundancy, but I think the solution you're looking for should be something revolving around this strategy. Make your 2 separate firewalls a single HA cluster. Take the 2 internet circuits and setup ISP redundancy on the cluster rather than 2 individual gateways as you have it now.
__________________
There's no place like 127.0.0.1
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:23.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.1