CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > ISP Redundancy
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-14
EBnycLuis EBnycLuis is offline
Junior Member
 
Join Date: 2007-01-31
Posts: 10
Rep Power: 0
EBnycLuis has an average reputation (10+)
Default VPN + ISP Links

Hey guys, new to the forum. Gotta say, i love the CP fw =)
Well My boss has me setting up the fw for isp fail over.

ex:

Internet ---------->10.10.1.1(rt)---> 10.10.1.2(fw)->office
Internet -----------|DSL Backup(rt)12.12.1.1----|12.12.1.2


Now, i have set it up for Primary/Backup, so when the t1 which is the 10.10.1.X link goes down, the DSL Backup takes over. NOW, heres the problem. since it knows the next hop from 10.10.1.2 is 10.10.1.1, if i disconnect the wire that goes from the rt to the fw, it knows and switchs over to the the dsl backup just fine. BUT if i disconnect the wire that goes from the internet to the rt, it doesnt detect!

1) is the detection of the failover before the wire coming out of the router
2) vpn to work as well with the dsl backup on failover?
3) i am trying to figure out how to setup the box for only 1 or maybe in the future more, dns address for our internal email servers for external access.

any help would be greatly apprciated! (sp)

-Luis
Reply With Quote
  #2 (permalink)  
Old 2007-02-14
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 358
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: VPN + ISP Links

You should use a host further up than the router for the checks.

I usually just do a traceroute and use the 2nd ISPs router (the one on the other side of the line) if it allows ping. Failing that some of their DNS servers, since those should allow ping.
Reply With Quote
  #3 (permalink)  
Old 2007-02-14
EBnycLuis EBnycLuis is offline
Junior Member
 
Join Date: 2007-01-31
Posts: 10
Rep Power: 0
EBnycLuis has an average reputation (10+)
Default Re: VPN + ISP Links

I tried that, and the link didnt come up. most likely b/c the link didnt allow pings. =\. ok i will try the next hop over for this. but, question... i can put this in the "next hop ip address" for the main line? so ex:10.10.1.1 is the "gw" to the fw (10.10.1.2) will it work if i put the IP address i want to monitor outside of the router? ex.. 188.123.123.1 which would be the next router down the line outside the building? or will it not work?
Reply With Quote
  #4 (permalink)  
Old 2007-02-14
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 358
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: VPN + ISP Links

It seems I wasn't that clear, let me explain this a bit better.

When you Edit the "ISP Link", the next hop has to be the gateway, but then you have the "Advanced" tab, where you can add "Monitored hosts".

So leave your config as is, but do the traceroutes to get the next hops after your edge routers for both ISPs, or some DNS servers or something "fairly close that accepts ICMP".

Create these hosts objects with their IP addresses and then add them in the Advanced tab.

Hope that helps.

Last edited by MarioL; 2007-02-14 at 08:36.
Reply With Quote
  #5 (permalink)  
Old 2007-02-14
EBnycLuis EBnycLuis is offline
Junior Member
 
Join Date: 2007-01-31
Posts: 10
Rep Power: 0
EBnycLuis has an average reputation (10+)
Default Re: VPN + ISP Links

ill try that now
Reply With Quote
  #6 (permalink)  
Old 2007-02-14
EBnycLuis EBnycLuis is offline
Junior Member
 
Join Date: 2007-01-31
Posts: 10
Rep Power: 0
EBnycLuis has an average reputation (10+)
Default Re: VPN + ISP Links

How about the vpn part?
Reply With Quote
  #7 (permalink)  
Old 2007-02-15
MarioL MarioL is offline
Senior Member
 
Join Date: 2007-01-18
Location: London
Posts: 358
Rep Power: 2
MarioL has an average reputation (10+)
Default Re: VPN + ISP Links

Considering the IPs you are using on the external interfaces I foresee a VPN nightmare... you should always use valid public IPs (assigned to you) on the external NICs.

I haven't been using FW-1 properly for some time now, so I never tried the new cool VPN features, so I can't help there, sorry.
Reply With Quote
  #8 (permalink)  
Old 2007-02-15
EBnycLuis EBnycLuis is offline
Junior Member
 
Join Date: 2007-01-31
Posts: 10
Rep Power: 0
EBnycLuis has an average reputation (10+)
Default Re: VPN + ISP Links

Well it worked like magic the host detection. i just hope that host never fails! =)

the vpn part is still not working thou, seems where i go to renew the certificate for the vpn connection, i put the ip of our backup line and still no vpn connection once the lines failed over.

they are public ips. the ips i provided are just examples ;)
Reply With Quote
  #9 (permalink)  
Old 2007-03-07
Izzio Izzio is offline
Member
 
Join Date: 2006-04-07
Location: Penzberg, Germany
Posts: 30
Rep Power: 0
Izzio has an average reputation (10+)
Default Re: VPN + ISP Links

...if with "vpn" you mean a vpn site2site tunnel with another CP FW then you need to set up the link selection feature.

Which version are you using?
Reply With Quote
  #10 (permalink)  
Old 2007-07-18
EBnycLuis EBnycLuis is offline
Junior Member
 
Join Date: 2007-01-31
Posts: 10
Rep Power: 0
EBnycLuis has an average reputation (10+)
Default Re: VPN + ISP Links

Hey guys, after getting the techs on this we solved it along time ago but i havnt been able to find this site =)

the problem was with allowing a policy for RDP on the vpn allowed. we noticed it would work for a few seconds but then it was blocked. so we knew it was a policy issue somewhere, just didnt know where.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:41.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0