CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > ISP Redundancy
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-25
Junior Member
 
Join Date: 2006-05-25
Posts: 6
Rep Power: 0
jparnell has an average reputation (10+)
Default ISP Monitored Hosts

Hi,

we've just implemented ISP redundancy on two Nokia IP350s, with Checkpoint NGX.

I notice that there is an option to configure 'ISP Monitored Hosts' which allow the firewalls to monitor hosts out on the internet, and mark the ISP link down if one of these hosts is does not respond.

I was wondering if anyone uses this option? Its sounds quite a good idea, but then I'm a little hesitant because if one of the monitored hosts is down for whatever reason ( maybe maintenance) then our ISP link will be marked down.

It can be found: Gateway Properties-> Topology-> ISP Redundancy-> ISP Links-> Edit-> Advanced.

Any views would be appreciated.

James

Last edited by jparnell; 2006-09-25 at 08:35.
Reply With Quote
  #2 (permalink)  
Old 2006-09-25
Senior Member
 
Join Date: 2006-07-10
Posts: 164
Rep Power: 3
Porter has an average reputation (10+)
Default Re: ISP Monitored Hosts

use something like google.com, the gw would ping then the loadbalancer in front of the webservers. Balancers are up in 99% of all cases, never had any problems with doing it like that way

by the way, which setup do you use? Primary/backup or loadsharing?
__________________
misery is optional
Reply With Quote
  #3 (permalink)  
Old 2007-03-21
Senior Member
 
Join Date: 2006-10-23
Posts: 168
Rep Power: 3
Danielpb has an average reputation (10+)
Default Re: ISP Monitored Hosts

I have a strange issue to add to this I have removed some of the monitored host's and just left a one available, pushed the policy ....but yet in the logs you can still see it ping the others I have removed.

any ideas?

cheers

Dan
Reply With Quote
  #4 (permalink)  
Old 2007-03-22
Junior Member
 
Join Date: 2007-03-21
Posts: 1
Rep Power: 0
widget has an average reputation (10+)
Default Re: ISP Monitored Hosts

HI,

we've got the same issue with the monitored hosts, I had a number in there but now just have google.com, but in smartview tracker you can see all the old entries being pinged as well.

I have a support call open with checkpoint on this.

Graham
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 09:01.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0