CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > ISP Redundancy
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-06-13
jsmwalker jsmwalker is offline
Junior Member
 
Join Date: 2008-04-15
Posts: 6
Rep Power: 0
jsmwalker has an average reputation (10+)
Default ISP LoadBalance / VPN Site to Site

Hi

New to Checkpoint, we have a load balanced ISP setup, one is a 4Meg Leased Line, the other 19Meg ADSL line, the way we want this to work is that the 19Meg is the primary line, which we can setup and get working fine, however this then breaks the site to site VPN's as they run across the 4Meg connection, have tried to bind them to this interface but does not seem to work, can anyone give me a rough guidline as to what needs to be set, we are running a Crossbeam with R60A Checkpoint.

Cheers in advance.

J
Reply With Quote
  #2 (permalink)  
Old 2008-06-13
Danielpb Danielpb is offline
Senior Member
 
Join Date: 2006-10-23
Posts: 160
Rep Power: 2
Danielpb has an average reputation (10+)
Default Re: ISP LoadBalance / VPN Site to Site

Hi

I think static routes might be able to resolve the VPN link route issues..not sure how this is added on a crossbeam system.

So the route would be

Dst Peer ##.##.##.##/32- next hop 19mb lease line router.
you might also need to add route the encryption domains(subnets) for that peer down the 19mb router.

Also do a search on this forum as I think with ISP redundancy checkpoint routes certain traffic down the primary connection, especial if you have your own mail relay box behind the firewall.
Reply With Quote
  #3 (permalink)  
Old 2008-06-13
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 993
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: ISP LoadBalance / VPN Site to Site

With ISP Redundancy then all Static NAT is sent out via the primary interface if in load balancing mode. Hide Nat is balanceed across both.

If you want to route your VPN tunnels down a line then turn off ISP Redundancy and just use static routes via the 4Mb line. You will need a route for the VPN Gateway, you will also then probably need to add a route for the encryption domains via the 4Mb line.
Reply With Quote
  #4 (permalink)  
Old 2008-06-16
jsmwalker jsmwalker is offline
Junior Member
 
Join Date: 2008-04-15
Posts: 6
Rep Power: 0
jsmwalker has an average reputation (10+)
Default Re: ISP LoadBalance / VPN Site to Site

Ok, seem to now have got this working, however, it seems that using the VPN link selection works, but I seem to have to apply the primary/backup interfaces, apply this, then deselect the correct VPN link selection, apply, then select the correct link selection and all works.

But this has left me with one problem, with Static Nat's on one server, this server is now unable to communcate with the outside world (another server seems unaffected so not sure why) However reading the documentation it appears I need to setup a Hidden Nat, which is fine and the server can communcate with the outside world, however the nat does not appear to work on the backup route (4mb line)

This is all getting quite frustrating, am sure its my inexperience with the Checkpoint, but there does appear to be some weirdness' here (guess all equipment has its strange behaviour)

Basically the server that needs access to the outside world is 192.168.1.1 for example, and only needs smtp published, surely i just create a hide rule saying:

Destination Outside 4mb IP
Port Smtp
Translated 192.168.1.1
Port smtp

And that should all work?

Any help sooooo gratefully received.

J
Reply With Quote
  #5 (permalink)  
Old 2008-06-18
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 993
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: ISP LoadBalance / VPN Site to Site

Hide NAT if you have ISP Redundancy needs to be set to Hide Behind Gateway so that it hides behind the gateway interface that it leaves from.

There is also an excellent article in Check Point knowledgebase that explains exactly what needs to be done to create working Static NAT and Hide NAT with ISP Redundancy as it is not the same as in normal mode where you need to create dynamic objects and then define them on the local boxes themselves to get it to work.
Reply With Quote
  #6 (permalink)  
Old 2008-06-18
jsmwalker jsmwalker is offline
Junior Member
 
Join Date: 2008-04-15
Posts: 6
Rep Power: 0
jsmwalker has an average reputation (10+)
Default Re: ISP LoadBalance / VPN Site to Site

Have tried this, but will give it another go, just didn't know if I am missing something really obvious (as don't understand why the other connection remained working with a static Nat, and this one failed!!!)

J
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:02.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0