CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Miscellaneous
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-05-30
Binary_01 Binary_01 is offline
Junior Member
 
Join Date: 2006-03-10
Posts: 17
Rep Power: 0
Binary_01 has an average reputation (10+)
Default Static Routing and VPN Domain

Setup: NGX R62 on SPLAT in HA

Ok I have 2 gateways in a vpn mesh. Those 2 gateways also have a Lan Extension between each other.

Basically the lanex terminates on the physical interfaces of both firewalls.

Right now, even if I added a static route to route the traffic via the LanEx, the traffic still gets routed via the VPN tunnels.

Ideally, I would like to take advantage of my 100mbit lanex and use it in priority and use the VPN tunnel as a failover.

Can someone point me in the right direction?

Regards,
Reply With Quote
  #2 (permalink)  
Old 2007-05-30
Binary_01 Binary_01 is offline
Junior Member
 
Join Date: 2006-03-10
Posts: 17
Rep Power: 0
Binary_01 has an average reputation (10+)
Default Re: Static Routing and VPN Domain

I have a feeling that it has to do with the vpn_route.conf file...
Reply With Quote
  #3 (permalink)  
Old 2007-06-06
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 983
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: Static Routing and VPN Domain

Apologies if you have already been told this, In terms of Check Point routing then I understand (from being told by Check Point) that if there is a VPN between two gateways then this takes precedence over static routes.

What I would suggest that you do is place a pair of routers between the LAN and the Check Point and then plug the LANEX into the Routers. You can then use the Routers to control routing, with the VPN being there as a secondary route.
Reply With Quote
  #4 (permalink)  
Old 2007-06-07
Binary_01 Binary_01 is offline
Junior Member
 
Join Date: 2006-03-10
Posts: 17
Rep Power: 0
Binary_01 has an average reputation (10+)
Default Re: Static Routing and VPN Domain

Thank you for replying, this was actually my plan B, Plan B setup is what I saw in other companies.

But my boss insists that the LanEx passed thru the Firewall.

Now I'm thinking that I should be able to do what I want by creating a site to site vpn tunnel with the other checkpoint connected at the other end of the LanEx.
So my two sites would have redundant VPN links with each other. One thru the LanEx and one thru the internet.

What do you guys think about that? Will I be able to set a metric on the LanEx VPN and use the Internet VPN as failover? Will I need to use SPLAT pro to do this? We don't have SPLAT Pro and prefer to keep it simple and not use any routing protocols. I would find it odd if this would not be supported... We should be able to create redundant VPN tunnels and set metric like we do with routers. I guess I would have to setup a traditional VPN in order to accomplish this.
Reply With Quote
  #5 (permalink)  
Old 2007-06-10
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,627
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Static Routing and VPN Domain

You can use VPN link selection to do this.

Use VPN->Link Selection->Use a Probing Method->Using on going Probing
Reply With Quote
  #6 (permalink)  
Old 2007-06-13
Binary_01 Binary_01 is offline
Junior Member
 
Join Date: 2006-03-10
Posts: 17
Rep Power: 0
Binary_01 has an average reputation (10+)
Default Re: Static Routing and VPN Domain

I appreciate your input!!

Thanks guys!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 21:04.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0