CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Dynamic Routing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-25
Junior Member
 
Join Date: 2006-03-09
Posts: 11
Rep Power: 0
craxnet has an average reputation (10+)
Default OSPF on NGX with Windows Server as Default Gateway

Hello.

we have built a route based topology network with our vpn satellites (NGX 60) and we want the routes to be switched automatically between two interfaces (VPN / WAN) in case of a connection breakdown. typicall failover.

so our core switches are distributing the networks to all communicating firewalls in this vpn. their are shown in ospf and also as ospf neighbours.

In some networks we implemented an windows domain controller (win2003 SP1) is the default gateway. this gateway decides when to use the path over the vpn tunnel or over the WAN connection.

our problem is now.
If the lan interface on the FW is going down the windows routing can notice that and switches over to the WAN router immedately. but if the internet connection with the vpn tunnel gets lost, nothing happens because the windows server can still "see" the lan interface.

so what can be do to change that?

if we place an additional interface into the firewall for WAN we create another single point of failure, and clusters are to exensive for this sites.

i hope anybody has a hint.
Reply With Quote
  #2 (permalink)  
Old 2007-01-26
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 465
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: OSPF on NGX with Windows Server as Default Gateway

possible use of RIM? Route injection mechanism in checkpoint?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 06:47.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0