CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Dynamic Routing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-18
yogi_ccse yogi_ccse is offline
Member
 
Join Date: 2006-11-08
Posts: 55
Rep Power: 2
yogi_ccse has an average reputation (10+)
Default Configuring routing protocol on FW

Hi,
Why one should not configure dynamic routing protocols on FW? What is the harm?
Can anyone please justify this statement with links to some sites (cisco, SANS, Checkpoint) which support this?

Reg.
YT
Reply With Quote
  #2 (permalink)  
Old 2007-09-18
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 539
Rep Power: 10
BarryStiefel has disabled reputation
Default Re: Configuring routing protocol on FW

Quote:
Originally Posted by yogi_ccse View Post
Hi,
Why one should not configure dynamic routing protocols on FW? What is the harm?
Can anyone please justify this statement with links to some sites (cisco, SANS, Checkpoint) which support this?

Reg.
YT
I recommend against having dynamic routing protocols on the Security Gateway for two reasons:

1. Many firewall problems are actually routing problems in disguise, so putting your dynamic routing on the same box as your Security Gateway makes it far more difficult to debug either of them.

2. By using dynamic routing, your Security Gateway has to trust the routing information updates it receives from other routers. This is a security risk; better to hard code them in as static routes.
__________________
Barry J. Stiefel ("Stee-ful")
CCSA/CCSE/CCSE+/CCSI
President, CPUG
Reply With Quote
  #3 (permalink)  
Old 2007-09-18
yogi_ccse yogi_ccse is offline
Member
 
Join Date: 2006-11-08
Posts: 55
Rep Power: 2
yogi_ccse has an average reputation (10+)
Default Re: Configuring routing protocol on FW

Thanks a million Dear friend! Can you please point me to some SANS/CP/Cisco links which has the same voice as i need to show it to my boss:)
reg.
YT
Reply With Quote
  #4 (permalink)  
Old 2007-09-19
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 895
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Configuring routing protocol on FW

I don't think you will find anything useful on Cisco site about why not to use Dynamic routing in firewalls as this is one of the selling points that Cisco use with there firewalls about how easy to add to a dynamic routing system.

With regards to Dynamic Routing on the Firewall, I would not place on any firewall that is an Internet Gateway, I would consider placing only on firewalls that are internal, or used with an MPLS cloud to encrypt your traffic over the MPLS network.

I know some places that actually place the default gateway on there Internet Firewall to point inwards so you have to have specific routes pointing to the Internet to be able to make a connection to it.

Search with Google on Firewall Best Practices

and it has links to cisco and sans regarding firewall best practices, there may be something in the docs that it references that is suitable.
Reply With Quote
  #5 (permalink)  
Old 2007-09-19
yogi_ccse yogi_ccse is offline
Member
 
Join Date: 2006-11-08
Posts: 55
Rep Power: 2
yogi_ccse has an average reputation (10+)
Default Re: Configuring routing protocol on FW

Thx Dear for your time and reply!
will search.

Reg.
YT
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:25.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0