CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > QoS (Quality of Service) (Formerly FloodGate-1)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-06-15
pointcheck pointcheck is offline
Junior Member
 
Join Date: 2007-04-29
Posts: 17
Rep Power: 0
pointcheck has an average reputation (10+)
Default QoS over VPN

What happens to marked packets on the internal network that connect through a Site-to-Site FW-1 VPN? I need to get my external router to make QoS decisions based upon packets that the clients have already marked. Does the firewall just pass them through without modification?

We do not have FloodGate/QoS installed on the firewall(s).

Thanks.
Reply With Quote
  #2 (permalink)  
Old 2007-06-20
mcnallym mcnallym is offline
Senior Member
 
Join Date: 2007-06-04
Posts: 857
Rep Power: 2
mcnallym has an average reputation (10+)
Default Re: QoS over VPN

I am a little confused by your question.

You are talking about asking the External Router, presumably this is a router outside of the Firewall, making QoS decisions on packets arriving over a VPN?

If this is the case then all that the External Router will see is encrypted packets from the site to site VPN, once these are decrypted then there would be no QoS on the packets.
Reply With Quote
  #3 (permalink)  
Old 2007-06-21
pointcheck pointcheck is offline
Junior Member
 
Join Date: 2007-04-29
Posts: 17
Rep Power: 0
pointcheck has an average reputation (10+)
Default Re: QoS over VPN

Quote:
Originally Posted by mcnallym View Post
I am a little confused by your question.

You are talking about asking the External Router, presumably this is a router outside of the Firewall, making QoS decisions on packets arriving over a VPN?

If this is the case then all that the External Router will see is encrypted packets from the site to site VPN, once these are decrypted then there would be no QoS on the packets.
Yes, that scenario is correct. For both inbound and outbound packets over the WAN which are VPN site to site, can the router make a QoS decision after the packets traverse FW-1?
Reply With Quote
  #4 (permalink)  
Old 2007-12-06
craxnet craxnet is offline
Junior Member
 
Join Date: 2006-03-09
Posts: 11
Rep Power: 0
craxnet has an average reputation (10+)
Default Re: QoS over VPN

Hi ...
i bet it will not make such sence to let an outgoing router make qos as long you are using a vpn link over the internet for example. the router even cannot read encrypted packets ... so you can only priorisize traffic within your vpn link but the internet providers will garantue nothing for traffic over the internet you rely on.


if u use mpls or atm for example you better ask your provider to mark specific traffic with dscp values ...
Reply With Quote
  #5 (permalink)  
Old 2007-12-12
fdamstra fdamstra is offline
Junior Member
 
Join Date: 2006-05-20
Posts: 28
Rep Power: 0
fdamstra has an average reputation (10+)
Default Re: QoS over VPN

Quote:
Originally Posted by pointcheck View Post
Yes, that scenario is correct. For both inbound and outbound packets over the WAN which are VPN site to site, can the router make a QoS decision after the packets traverse FW-1?
I can't answer your original question, as I don't know what checkpoint does with the TOS field of a packet that it's going to encrypt. However, I can disagree with the previous posters who said that it doesn't make sense.

In a Cisco world, the DSCP or IPP markings would be propagated upward to that same field of the encrypted packet, which would allow your router to continue to prioritize packets based on its marking, even though the source/destination/payload of those packets would at that point be encrypted. This is a sensible solution, and I would expect that CheckPoint would do the same (but they've been known to surprise me).

Of course, if the VPN is going over the Internet, the ISP's are going to ignore the markings and FIFO the packets, but you can get the benefits of prioritization at your edge routers (where congestion is most likely). If you're going over a private network that understands traffic markings, they should be processed appropriately based on their original tags.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 01:44.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0