CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > ISP Redundancy
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-08-14
underattack underattack is offline
Junior Member
 
Join Date: 2007-07-17
Posts: 10
Rep Power: 0
underattack has an average reputation (10+)
Default VPN / ISP redundancy architecture

Hello,

I am working on a solution with high-availibility and I would like to be sure about VPN and ISP redundancy.

If I have a firewall A with 2 ISP (primary link with ISP1/backup with IPS2), and a VPN with a firewall B, do firewalls A and B have to be managed by the same SmartCenter for the VPN/ISP redundancy to work ?

If a link fails on firewall A, how firewall B will know that it will have to go through the ISP2 link on the Firewall instead of ISP1 ?

As the Firewall A will have 2 public addresses, how will Firewall B learn the second IP address as the object is defined with 1 IP address ?

Can this work if the 2 Firewalls are not managed by the same smartCenter ?


If both Firewall A and B use ISP redundancy, will the VPN redundancy still work ?

Do I have to use interface VPN with dynamic routing for the redundancy ?

I realize this is a lot of question but I would a have a best understanding on how this works exactly to implement it.

Cheers,

Fabien
Reply With Quote
  #2 (permalink)  
Old 2007-08-16
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 1,027
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: VPN / ISP redundancy architecture

ISP Redundancy is seperate to VPN and VPN link selection is only tied to the ISP Redundancy Settings if the Enable for VPN is ticked in the ISP Redundancy page.

If you don't tick then which IP address is used is dependant upon how you configure the VPN Link selection.

However the remote VPN gateways do not have to be managed by the same SMARTCenter, you merely have to tell them about the extra interface, if Check Point can use MEP on the other SMARTCenter to tell about both IP addresses, or if non-Check Point just define as a backup gateway to the secondary link.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 16:17.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0