CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > ISP Redundancy
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-07-09
ktpoitm ktpoitm is offline
Junior Member
 
Join Date: 2007-06-28
Posts: 6
Rep Power: 0
ktpoitm has an average reputation (10+)
Default dns issue with ISP Redundancy?

Has anyone experienced dns issues when using the backup line, via the ISP Redundancy? dns is fine on the primary DS1, but when the cluster switches to the backup satellite connection, dns will not resolve correctly all the time. I can reach some sites and not others, pure hit and miss. I am running a SecurePlatform HA Cluster, NGX R60.

Thank you,
Reply With Quote
  #2 (permalink)  
Old 2007-07-11
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 993
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: dns issue with ISP Redundancy?

Are you talking about connecting from inside your local network to the Internet or from the Internet to your own hosted websites that isn't resolving properly.
Reply With Quote
  #3 (permalink)  
Old 2007-07-11
ktpoitm ktpoitm is offline
Junior Member
 
Join Date: 2007-06-28
Posts: 6
Rep Power: 0
ktpoitm has an average reputation (10+)
Default Re: dns issue with ISP Redundancy?

From inside the network going out to the Internet.

DNS resolves to 0.0.0.0 on some sites. Also, the Tracker log shows that some domain-udp requests originate from the management console and others originate from the enforcement point. We only see domain-udp requests originate from the management console when we fail over to the second line. I can not prove it, but I assume the sites we can not reach are the ones were the domain-udp requests originate from the management console.
Reply With Quote
  #4 (permalink)  
Old 2007-07-11
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 993
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: dns issue with ISP Redundancy?

How is your internal DNS setup, I presume all boxes point at an internal DNS server that is then setup with a forwarder to an ISP DNS Server for names outside of your domain

Have an object defined for the internal dns server and then hide nat behind the gateway. This will then just nat the outbound dns behind which ever link is active.

Sounds more like the NAT isn't correctly configured.

I don't really see how the gateway or management console would be the only ones performing dns lookups
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:13.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0