CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > ISP Redundancy
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-12-14
Ted Odom Ted Odom is offline
Junior Member
 
Join Date: 2006-11-06
Posts: 5
Rep Power: 0
Ted Odom has an average reputation (10+)
Default ISP Redundancy failover, impact to outbound non FW hosts

Is it possible for sessions initiated outbound to use the NAT associated with the remaining ISP interface that is not assigned to the firewall object?

I have SPLAT NGX 61 running with 2 ISP connections. Currently it is defined in Primary/Backup. The Email server has an IP address associated with each interface. I use manual address translation for incoming packets for each interface, 2 statement. Outgoing I also have manual address translation for each interface, 2 statements. I have defined a host route from each routable address to this host and have manually added an ARP entry for each external host address.

When both links are up every this works fine. I can shift to load sharing and both interfaces are used properly.

When I take the primary down the packets are still being translated using the primary static NAT so the packets are not routable through that interface.

If I use the “hid behind the gateway”, this is a different IP address than the host uses so conversations are not being handled over the same IP address.
Reply With Quote
  #2 (permalink)  
Old 2006-12-14
Ted Odom Ted Odom is offline
Junior Member
 
Join Date: 2006-11-06
Posts: 5
Rep Power: 0
Ted Odom has an average reputation (10+)
Default Re: ISP Redundancy failover, impact to outbound non FW hosts

It now works!!!!
Look at Checkpoint sk25152. It explains how to make the static nats for the primary interface not be used when it is down. It involves the use of dynamic objects in the NAT rules, dynamic commands as well a script updates to $FWDIR/bin/cpisp_update.

I following the instructions on our FW. I then pulled the primary interface. The outgoing Email now used the static NAT to the 2nd interface. I confirmed I was able to send and receive Email.

I tested this under both options, Load Balancing and Primary/Backup.
Reply With Quote
  #3 (permalink)  
Old 2006-12-18
eigrich eigrich is offline
Junior Member
 
Join Date: 2006-12-18
Posts: 8
Rep Power: 0
eigrich has an average reputation (10+)
Default Re: ISP Redundancy failover, impact to outbound non FW hosts

Quote:
Originally Posted by Ted Odom View Post
It now works!!!!
Look at Checkpoint sk25152. It explains how to make the static nats for the primary interface not be used when it is down. It involves the use of dynamic objects in the NAT rules, dynamic commands as well a script updates to $FWDIR/bin/cpisp_update.

I following the instructions on our FW. I then pulled the primary interface. The outgoing Email now used the static NAT to the 2nd interface. I confirmed I was able to send and receive Email.

I tested this under both options, Load Balancing and Primary/Backup.
Can you please send me the detail knowledge base? I cannot find sk25152 in checkpoint website. Maybe I don't have access to it??

Thanks
Reply With Quote
  #4 (permalink)  
Old 2006-12-19
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,648
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: ISP Redundancy failover, impact to outbound non FW hosts

Quote:
Originally Posted by eigrich View Post
Can you please send me the detail knowledge base? I cannot find sk25152 in checkpoint website. Maybe I don't have access to it??
You need advanced access (re a support contract or your CCSE) to see this one.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:20.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0