CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > ISP Redundancy
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-01
guy-1 guy-1 is offline
Junior Member
 
Join Date: 2007-02-11
Posts: 5
Rep Power: 0
guy-1 has an average reputation (10+)
Default How to monitor ISP links

Hi all,

I successfully use ISP redundancy with a vpn between two sites, in active/passive mode. Right now, the 2 links only monitor their respective next hop.

I recently had a failure of the primary ISP, but the failure was somewhere on the backbone of the ISP, so checkpoint didn't notice the link was down - i had to unplug the primary link to have the secondary take over.

I now planning to had hosts to the list of monitored host, for each ISP.

It occured to me that the best host to monitor would be the distant checkpoint gateway. It means, if I can ping the distant gateway, it will be available for vpn.

I have configured it on the secondary link, in order to test it. Well, it fails. The answer is in smartview tracker : "encryption failure: Clear text packet should be encrypted".

It means, the ping packets are sent by the secondary link, so it is not encrypted -> the receiving checkpoint gateway drops it because it is originating from a gateway to which there is a vpn.

Is there a way to allow unencrypted traffic between the gateways ? I mean, I want to have all the networks behind each gateways be encrypted between the gateways, but I can't find a way to have all the traffic between the gateways not be encrypted when they use their respective public ip addresses...

Anyone has an idea ?
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 22:22.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0