CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-12-01
Junior Member
 
Join Date: 2006-12-01
Posts: 4
Rep Power: 0
henke has an average reputation (10+)
Default Default Route to Logical Name??

Hope you can help. I'm trying to setup the default route on via Nokia Voyager to point out of an interface rather than to an IP address. I have deleted the default route and added it back in, rather than selecting IP Address, I selected Logical name so I could point it to on interface. When I apply this, it does work, the apply is accepted.

The problem is when I go to set the logical name, gateway is set to 'none' from the drop down menu. There is no list of interfaces, nor can I manually enter in the logical name. It is set to 'none' and cannot be changed.

Can the above be done? Or am I doing something completely stupid?

Any help/feedback would be greatly appreciated.
Reply With Quote
  #2 (permalink)  
Old 2006-12-01
Senior Member
 
Join Date: 2006-06-08
Location: UK
Posts: 149
Rep Power: 3
Joncon has an average reputation (10+)
Default Re: Default Route to Logical Name??

henke,

Why do you want to point the default route to an interface name rather than an IP address? I can't understand why you would want to do this, but there's obviously a reason.
Reply With Quote
  #3 (permalink)  
Old 2006-12-05
Junior Member
 
Join Date: 2006-12-01
Posts: 4
Rep Power: 0
henke has an average reputation (10+)
Default Re: Default Route to Logical Name??

Hi Joncon,

Yip, it is a bit of a bizarre setup. It is only a temporary measure as my customer wants to use their new Internet link. They are desperate for more bandwidth and the only place to connect their new circuit is directly into the Checkpoint FW. I know it goes against good practice, but it is only a temp measure until early Jan 07. The circuit is just an internet pipe from an ISP, so there is no remote IP address for next hop provided, hence the reason I want to just use a logical interface as the next upstream hop.

Any ideas?

Cheers,

Henke.
Reply With Quote
  #4 (permalink)  
Old 2006-12-05
Senior Member
 
Join Date: 2006-06-08
Location: UK
Posts: 149
Rep Power: 3
Joncon has an average reputation (10+)
Default Re: Default Route to Logical Name??

henke,

Has the ISP that has provided the new connection not installed a managed / border router for the connection? What kind of service has the customer bought? Have never setup a 'corporate' internet link without having an ISP supplied router. Has the ISP not assigned you a range of Public IPs to use with the new connection?
Reply With Quote
  #5 (permalink)  
Old 2006-12-05
Junior Member
 
Join Date: 2006-12-01
Posts: 4
Rep Power: 0
henke has an average reputation (10+)
Default Re: Default Route to Logical Name??

Hi Joncon,
Thanks for getting back to me. They haven't supplied a router. They have supplied a range of IP addresses. The customer has a router it will migrate from an existing internet link in Jan 07, this is just a temporary 'bodge' to get them through until that period and give them more bandwidth as they're existing bandwidth is maxed out. For a relatively small network, it is a very complex setup and whatever way I turn another hurdle appears.

I would have thought just pointing a default route out an interface would have been a relatively straightforward thing to do.

Cheers,

Kenny.
Reply With Quote
  #6 (permalink)  
Old 2006-12-05
Senior Member
 
Join Date: 2006-06-08
Location: UK
Posts: 149
Rep Power: 3
Joncon has an average reputation (10+)
Default Re: Default Route to Logical Name??

Ok. If the ISP has supplied a range of public IPs that are availible for you to use can you not assign one to the 'external' NIC on the FW that you want the new internet pipe connected to? You can then assign a default route through Voyager to route internet traffic to this IP.

You will need to think how the below will affect the organisation. Things to conside:-
1. DNS records.
2. MX records.

Personally, I would prefer to sit a router in front of the firewall that you can screen incomming traffic with and filter unwanted traffic out with an ACL. This would be your first line of defence and help to take the load off the FW. However, it appears the customer is desparate so it's your call. Either way I would explain the risks of not having a screening router.

Hope this helps,

Joncon
Reply With Quote
  #7 (permalink)  
Old 2006-12-07
Junior Member
 
Join Date: 2006-12-01
Posts: 4
Rep Power: 0
henke has an average reputation (10+)
Default Re: Default Route to Logical Name??

Thanks Joncon, I'll give it a try. They are going to arrange for their MX records etc to be updated. I explained to them that this is far from ideal and there is a certain degree of risk, even in a temporary setup.

Thanks for your help.

Henke.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 21:18.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0