EIGRP support and passive mode I'd love to be able to run Checkpoint in a passive firewall mode. Cisco's new ASA's can run in passive mode while still doing stateful inspection and providing application/presentation layer protection. I'd also love to see Checkpoint support passing EIGRP. It is a Cisco proprietary protocol, so obviously CP couldn't ever participate in EIGRP, but it would be nice to at least be able to pass the traffic between two Cisco routers/enterprise switches that you want to participate in EIGRP. |