CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Dynamic Routing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-08-28
Riqsta Riqsta is offline
Junior Member
 
Join Date: 2007-08-23
Posts: 2
Rep Power: 0
Riqsta has an average reputation (10+)
Default LAN Extension

Howdy,

A LAN Extension is being installed which will join our remote office and the hosting site. A router won't be in place until we've have our MPLS circuit installed. Just wondering is it possible to use the GWs to handle routing between the two sites.

The idea is to make it so the Gateways send LAN traffic through the LAN Extn and internet traffic through the external interface. Below is what's running at both sites.

Site A - Hosting Site
R62 on SPLATPRO
eth0 - External IP - 192.168.1.1
eth1 - Internal LAN IP - 10.10.6.1
eth2 - DMZ - 10.20.6.1
eth4 - LAN Extn IP - ???

Site B - Office
R62 on SPLATPRO
eth0 - External IP - 192.168.2.1
eth1 - Internal LAN IP - 10.10.7.1
eth3 - LAN Extn IP - ???

Rule Base for VPN
GW-to-GW (All Gateways)
Site-to-Site (All Protected Networks)

Would either of the following work:
Setup eth4 (HS) with 10.10.7.2 and hide the 10.10.7.0 LAN behind it and then setup eth3 (Off) with 10.10.6.2 and hide the 10.10.7.0 LAN behind it.

Setup eth4 (HS) with 10.10.7.2 and NAT it to a 10.20.6.2 IP address and then setup eth3 (Off) with 10.10.6.2 and NAT it to a 10.20.7.2 IP address.

If it won't work what will....besides a proper router.....

Cheers.
Reply With Quote
  #2 (permalink)  
Old 2007-08-30
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 895
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: LAN Extension

The LAN Extension being on a seperate interface will need to be a different IP range to the Internal Network.

However why not just add static routes that say that the remote networks are via the remote gateway.

This way the Internet traffic goes via Internet and the LAN traffic goes via the LAN.
Reply With Quote
  #3 (permalink)  
Old 2007-09-12
Riqsta Riqsta is offline
Junior Member
 
Join Date: 2007-08-23
Posts: 2
Rep Power: 0
Riqsta has an average reputation (10+)
Default Re: LAN Extension

Thanks mcnallym, it pointed me in the right direction however...

Connection speed for a 100Mb LANX is inconsisent and thus been unsatisfactory.

Site A - Hosting Site
R62 on SPLATPRO
eth0 - External IP - 192.168.1.1
eth1 - Internal LAN IP - 10.10.6.1
eth2 - DMZ - 10.20.6.1
eth4 - LANX IP - 10.30.6.1

Site B - Office
R62 on SPLATPRO
eth0 - External IP - 192.168.2.1
eth1 - Internal LAN IP - 10.10.7.1
eth3 - LANX IP - 10.30.6.2

Rule Base for VPN
GW-to-GW (All Gateways)
Site-to-Site (All Protected Networks)

Static Routes
10.10.7.0/24 to use GW IP 10.30.6.2 on Site A
10.10.6.0/24 to use GW IP 10.30.6.1 on Site B

I have confirmed that the routes are working.

My thought is that the LANX packets are being encrypted thus increasing the latency times.

Any one have any ideas to increase performance.

Cheers,
Riqsta
Reply With Quote
  #4 (permalink)  
Old 2007-09-13
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 895
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: LAN Extension

If you are running a VPN between the two gateways, and looking at it then I suspect that you are then it will encrypt.

Check Point always encrypts if there is a VPN between the src and destination.

You need to be more specific with your VPN configuration so that you specify where you VPN between and what networks. You are saying at the moment all gateways which will include the OfficeB gateway so it will encrypt.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:22.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0