CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Dynamic Routing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-29
randyb randyb is offline
Junior Member
 
Join Date: 2007-09-28
Location: San Diego, CA
Posts: 1
Rep Power: 0
randyb has an average reputation (10+)
Default WAN link failover to VPN

Hi all:
I am wondering how to go about implementing VPN failover for remote office T-1 links. We have an IP350 cluster at HQ with several networks behind multiple interfaces. The remote offices aggregate behind one of the interfaces and are connected via T1 WAN links. We have been deploying SofaWare Safe@ Office devices to the remote offices to take the Internet traffic off of the T1 links, and now management wants to make the circuits redundant by configuring the endpoints to fail over to the VPN if the serial goes down. I know both ends can do OSPF and/or route-based VPNs, I would just like some direction on how to move forward. Has anyone done this before?

Thanks!
Randy B
Reply With Quote
  #2 (permalink)  
Old 2007-09-30
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 895
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: WAN link failover to VPN

Bad news. You cannot Route base VPN between Sofaware/Edge boxes and Nokia's. You can do route based VPN's between Sofaware/Edge and SPLAT boxes, and SPLAT boxes and Nokia, but not Nokia to Sofaware/Edge.

The other peice of info that is relevant is that if you have a VPN between two points then it will automatically route via the VPN even if routing costs are set so that the lease line is a lower cost. You would need to have a router in front of the firewall boxes to make the routing decision, wether to goto the firewall or go via a lease line.

Your remote offices would then need to be plugged into routers that don't go via the Nokia's to get to the internal main office networks.

Also please note that the Safe@500 boxes need the Power Pack upgrade to be able to do the OSPF routing.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:29.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0