CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Dynamic Routing
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-10-16
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 234
Rep Power: 3
lammbo has an average reputation (10+)
Default Temporarily re-direct traffic to another site

(WHAT I WOULDN'T GIVE FOR F5 BOXES INSTEAD OF ASKING THIS QUESTION)

SCS = R65 (HA)
Old ATL Gateways = R60 HFA_04 (New mode ClusterXL HA)
New ATL Gateways = R65 (New mode ClusterXL HA)

VPN is traditional mode with pre-shared secrets


We are currently in a position where we will be moving our Hosting services site to a new CO-LO in ATL. I already stood up new firewalls at the new site. The new site will have non-overlapping internal subnets and new external address ranges. Most of the traffic from clients is 80/443. The move will be completed in phases with as little down time as possible.

Needless to say, when we move web servers, there will be a very large DNS mess.

In an effort to make the transition as smooth as possible, is there a way to redirect traffic arriving at the old site to the new site using the firewalls so we can proceed more cautiously than an all-at-once deal?
__________________
There's no place like 127.0.0.1
Reply With Quote
  #2 (permalink)  
Old 2007-10-16
dantro dantro is offline
Senior Member
 
Join Date: 2007-02-07
Location: Halle (Saale)
Posts: 200
Rep Power: 2
dantro has an average reputation (10+)
Default Re: Temporarily re-direct traffic to another site

I'd recommend using NAT.
Reply With Quote
  #3 (permalink)  
Old 2007-10-26
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 234
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Temporarily re-direct traffic to another site

Anyone out there have experience with ConnectControl?

I'm being told that this is basically a scaled down version of what F-5 can do, but I see no mention of different sites being involved. Also, I was told R65 was OK as well, but the supported platforms on the list stop at R62 on the website.

All I can find regarding documentation is the 2 page data sheet. If anyone knows where the documentation is, please provide a link so I can do my homework.
__________________
There's no place like 127.0.0.1
Reply With Quote
  #4 (permalink)  
Old 2007-10-27
dsb.nepo dsb.nepo is offline
Senior Member
 
Join Date: 2006-04-30
Location: Europe, Germany
Posts: 131
Rep Power: 3
dsb.nepo has an average reputation (10+)
Default Re: Temporarily re-direct traffic to another site

Quote:
Needless to say, when we move web servers, there will be a very large DNS mess.
If you have full access to the dns zones or you are the primary dns then there are some ways to minimise problems (SOA records).

Quote:
In an effort to make the transition as smooth as possible, is there a way to redirect traffic arriving at the old site to the new site using the firewalls so we can proceed more cautiously than an all-at-once deal?
I don't know the volume, but maybe it is possible to work with mapped service to minimise the effect
old site: ip1 -> http_mapped_ip1 (80,new_ip(via vpn),80)

also I can think about a dedicated balancer behind the old FW that do the redirect (OpenBSD comes in my mind very intuitive and fast to setup)
Reply With Quote
  #5 (permalink)  
Old 2007-11-09
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 857
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Temporarily re-direct traffic to another site

Is buried in the Firewall and SMARTDefense guide, if want the manual for Connect Control. As you already realise is no way near an F5 but may be enough for you.

Isn't cheap though, as is $8000 on price list per gateway, and isn't part of the standard VPN-1 license.

I had a customer ask about it recently which I had to refresh for.
Reply With Quote
  #6 (permalink)  
Old 2007-11-15
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 234
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Temporarily re-direct traffic to another site

Thanks for all the info guys!

Management has finally abandoned the re-direct notion. The plan is now to move the BGP advertisements to the new data center while we are down during the move (both Data Centers are onboard with this). Of course, this now adds a different challenge (or if my assumption is correct, no impact).

More topology info:
All gateways managed by same SCS (R65 HFA_02)
Each site has it's own Policy - set to install only to it's appropriate gateway cluster
SiteA (old) (R60 HFA_04)
SiteB (new) (R65 HFA_02)
SPLAT gateways using Auto-NAT
OldHost@SiteA has x.x.x.x as NAT - Only set to NAT at SiteA (not ANY)
NewHost@SiteB has x.x.y.x as NAT - Only set to NAT at SiteB (not ANY)


When I started this, I stood up the new firewalls with new subnets. I cloned every host object (we'll call this OldHost@SiteA) from the old site. When I did this, I renamed the cloned host (we'll call this NewHost@SiteB); I changed private IP octets 2 and 3 to match the new site's topology and changed the Public IP for the exposed servers to match what was going to be, in the original plan, the new Public IP range (only the 3rd octet changed).

With this new development, I will have to go back to these NewHost@SiteB hosts and change back the 3rd octet on the Public IP.

Given this information and the fact that BGP will not be advertising at SiteB until we go down for the move, is it possible for me to pre-change NewHost@SiteB back to the original NAT from Site A x.x.x.x, as opposed to x.x.y.x, and still be able to push policy without breaking the NAT at SiteA.

My thoughts on this are that I should be able to do so because the NAT is set to install only to a specific gateway. Therefore, when I push policy to SiteA, it will not try to auto-NAT using SiteB private IPs since the NAT is not installed on that cluster for cross-site hosts.

NewHost@SiteB will now have the same Public IP as OldHost@SiteA in the rulebase/NAT table, but SiteA should continue to function even though SiteB is ready for the hosts as soon as BGP adverts start at SiteB.

Is this a correct assumption? Otherwise, the fallback plan is that I change everything in the rulebase now and can't push policy until SiteA is down @ 3AM on Sunday.
__________________
There's no place like 127.0.0.1

Last edited by lammbo; 2007-11-15 at 08:09. Reason: typos
Reply With Quote
  #7 (permalink)  
Old 2007-11-15
lammbo lammbo is offline
Senior Member
 
Join Date: 2006-02-09
Location: Charleston, SC
Posts: 234
Rep Power: 3
lammbo has an average reputation (10+)
Default Re: Temporarily re-direct traffic to another site

My support team confirmed this should not be an issue.

I just tested using a host that I could break without customer impact and everything works as I suspected on my live systems.

Policy can be pushed when 2 hosts have the same static IP as long as you set the NAT to install on just it's own gateway and not ALL gateways.

So once my BGP adverts move to the new site, all of the hosts are already setup using the same static/hide NAT they used at the same site.

Hope this write-up helps someone else in the future.

(Hey, this is my 100th post! Senior Member, woo hoo!)
__________________
There's no place like 127.0.0.1
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:01.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0