CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > QoS (Quality of Service) (Formerly FloodGate-1)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-02-04
Junior Member
 
Join Date: 2007-06-20
Posts: 4
Rep Power: 0
drewishus has an average reputation (10+)
Default Can ToS flags (DSCP) be forwarded across Floodgate?

Hi,
I'm not a pro with the QOS stuff, but I understand most of it. I've read the CP docs and scoured the forums and am really having trouble figuring this out:
If I have devices upstream and downstream of the firewall that are marking packets, can I simply allow the markings to persist through the firewall?
By default, it appears that the answer is 'no', but I'm hoping there is an easy way to preserve markings being sent across the firewall.

Currently:
[router-a]-->(dscp packet1)-->[FW]-->(no dscp)-->[router-b]
[router-a]<--(no dscp)<--[FW]<--(dscp packet2)<--[router-b]

Desired:
[router-a]-->(dscp packet1)-->[FW]-->(dscp packet1)-->[router-b]
[router-a]<--(dscp packet2)<--[FW]<--(dscp packet2)<--[router-b]

I know I could write a rule that identifies interesting traffic and rewrites the header for me, but then we've got a bit of a management nightmare for any policy changes to ToS. Does anyone have any ideas?
Thanks!

Andrew
Reply With Quote
  #2 (permalink)  
Old 2008-03-04
Senior Member
 
Join Date: 2006-12-16
Posts: 162
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: Can ToS flags (DSCP) be forwarded across Floodgate?

no, Checkpoint can not forward these flags. Checkpoint qos can create different classes but not forward from an upstream cisco.
Reply With Quote
  #3 (permalink)  
Old 2008-04-15
Member
 
Join Date: 2007-04-11
Location: Paris, France
Posts: 63
Rep Power: 2
Tan Da Boss has an average reputation (10+)
Send a message via MSN to Tan Da Boss
Default Re: Can ToS flags (DSCP) be forwarded across Floodgate?

Thanks Routerkid1 for this answer.
Do you know if the next NGX R65 VoIP will include this functionnality?

Cheers

Tan
Reply With Quote
  #4 (permalink)  
Old 2008-04-18
Member
 
Join Date: 2007-04-11
Location: Paris, France
Posts: 63
Rep Power: 2
Tan Da Boss has an average reputation (10+)
Send a message via MSN to Tan Da Boss
Default Re: Can ToS flags (DSCP) be forwarded across Floodgate?

Quote:
From Check Point's documentation

Question: Should I install Check Point QoS on the external or the internal interface?
While Check Point QoS can run on both interfaces, it is highly
recommended to position Check Point QoS on the external interface only.
Has anybody already implemented QOS on internal and external interfaces?
I chatted with CP's TAC and she just told me that it might be a performance issue.
One of my customer has a firewall "between" two WANs and he has to use Diffserv on both sides of his firewall.

any feedback would be appreciated.

Thanks

Tan
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 17:11.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0