CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 Platforms > Nokia And IPSO
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-05-17
the_chicco the_chicco is offline
Junior Member
 
Join Date: 2006-05-17
Posts: 2
Rep Power: 0
the_chicco has an average reputation (10+)
Default Moving Nokia platform

Hey all.

I am a relative newbie when it comes to Checkpoint, my main areas being Pix, Netscreen, etc so please be gentle.

I have just aquired a Nokia IP330 from eBay for a good price, it's only sitting on FW-1/VPN-1 v4.1 but it does come with Enterprise software and subscription support until January 2007 so it can be upgraded.

The IP330 being an old bit of kit, I was hoping to get a more powerful Nokia from eBay and use this instead. Is that possible?

Also would there be any issues with this sitting behind a Cisco 1751 connected to an ADSL line with the External IP of the Nokia being on a private LAN range?
Reply With Quote
  #2 (permalink)  
Old 2006-05-17
rubber_chicken rubber_chicken is offline
Member
 
Join Date: 2006-03-08
Location: New Zealand
Posts: 84
Rep Power: 3
rubber_chicken has an average reputation (10+)
Default Re: Moving Nokia platform

Hi,

It depends a bit on what you plan to do with the connection.

The IP330 was a decent piece of kit and I had 250 users sitting behind one sharing a 4mb internet connection. The only time it ever wobbled was when I tried to pull 200GB over it. (DMZ to Trusted @ 100MB/s) As it didn't have hardware VPN acceleration the CPU ran a little high as we had 20 site to site VPNs and about another 20 concurrent SecureClient connections terminating on it.

So if you are putting it on an ADSL connection, you should be fine.

As for the networking, you should be fine, although you may have issues with NAT if you have a big address pool.
Reply With Quote
  #3 (permalink)  
Old 2006-05-18
the_chicco the_chicco is offline
Junior Member
 
Join Date: 2006-05-17
Posts: 2
Rep Power: 0
the_chicco has an average reputation (10+)
Default Re: Moving Nokia platform

Hey,

thanks for the reply Rubber_Chicken.

It's literally just going to be for me. 8MB ADSL link and I will have my 3 x vmware esx boxes sitting behind it, running probably 10/15 instances of 2003/ redhat es. Will have some light smtp (exchange) & http (iis / apache)traffic, dc replication, possibly 1 or 2 vpns terminating on it.

The NAT pool will be small (have only 8 publics), I only need a few to boxes to sit in the DMZ.

A 330 sounds fine for my needs then :)
Reply With Quote
  #4 (permalink)  
Old 2006-05-20
Lackie Lackie is offline
Senior Member
 
Join Date: 2005-08-22
Location: Ottawa, Canada
Posts: 347
Rep Power: 4
Lackie has an average reputation (10+)
Default Re: Moving Nokia platform

Quote:
Originally Posted by the_chicco
A 330 sounds fine for my needs then :)
This will be plenty for your own use.
Reply With Quote
  #5 (permalink)  
Old 2006-06-07
zyz101z zyz101z is offline
Junior Member
 
Join Date: 2006-06-07
Posts: 12
Rep Power: 0
zyz101z has an average reputation (10+)
Default Re: Moving Nokia platform

The only thing I would watch out for on the IP330's is hard drives. The hard drives on them seem to crash way more often than other IP series servers. I used to work for a MSP where we managed about 200 IP330's. After they got a bit older we would have a server crash due to hard drive issues almost weekly. The IP350's are way better boxes. However, performance wise the 330's are very solid.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:54.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0