CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > QoS (Quality of Service) (Formerly FloodGate-1)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-02-15
pbkirk pbkirk is offline
Junior Member
 
Join Date: 2007-02-15
Posts: 1
Rep Power: 0
pbkirk has an average reputation (10+)
Default NGX R60 QoS, IPSEC and ClusterXL - FTP DiffServ Marking

I'm having problems getting CP SPLAT to properly mark DiffServ for FTP traffic over an encrypted link. The VPN community includes a remote Gateway's inside LAN segment and central site cluster inside LAN segment.

I've added the SPLAT and FW hotfixes to all gateways/cluster members and Smartcenter Server, performed some tests, and here's what I found. I can get a single Gateway to mark FTP packets with Diffserv on a traffic flow between a host (on remote Gateway's inside LAN segment) and central site server (on inside cluster LAN segment), but the cluster will not mark the packets. It doesn't matter what direction the connection and transfer occur in (RMT to CS or vice versa), no packets sourced from central site are ever marked. It's almost as if the QoS Diffserv should be applied to the physical interfaces instead of the Cluster interface IP, but the object's topology edit won't let you do that (there's not a QoS tab for the physical interfaces, just for the cluster interface). Has anyone else had this problem?
Reply With Quote
  #2 (permalink)  
Old 2007-03-08
Yasushi Kono Yasushi Kono is offline
Senior Member
 
Join Date: 2006-10-03
Location: Offenbach/ Germany
Posts: 104
Rep Power: 2
Yasushi Kono has an average reputation (10+)
Default Re: NGX R60 QoS, IPSEC and ClusterXL - FTP DiffServ Marking

you have to alter the global properties. Launch GuiDBedit and look for the parameter :ipsec.copy_TOS_to_inner and :ipsec.copy_TOS_t_outer.

You should set both parameters to true. That' s it.
Of course, you could modify these settings with dbedit. You should be familiar with this tool.

Kind regards,
Yasushi
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 02:14.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0