CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > QoS (Quality of Service) (Formerly FloodGate-1)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2008-06-11
steve_mils steve_mils is offline
Junior Member
 
Join Date: 2008-06-11
Posts: 2
Rep Power: 0
steve_mils has an average reputation (10+)
Default Checkpoint and QoS in a cisco network

Hi,

We have a Cisco network that has end-to-end QoS deployed using Cisco best practices. For example, we have access-layer switches that classify and mark packets from end-user PCs. Upstream switches / routers can then act on those markings and queue packets accordingly.

We also use Checkpoint firewalls between our HQ and remote offices and at the moment they do not have QoS enabled. So in effect we have end-to-end QoS from the Cisco point of view; but the firewall is a gap at present.

My question is does anyone know what's happening to our packets as things stand? For example I'm sending a mixture of services marked as EF, AF11, AF12, AF21, AF22 etc. Do the Checkpoints remark the Qos markings at all? I'm hoping that they don't alter to markings at all because I have a router the other side of the Checkpoint which needs to see those markings!

Thanks
Reply With Quote
  #2 (permalink)  
Old 2008-06-13
sebastan_bach sebastan_bach is online now
Senior Member
 
Join Date: 2005-10-12
Posts: 315
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: Checkpoint and QoS in a cisco network

hi steve even i had this query long time back.but someone in the forum mentioned checkpoint doesn;t retain the markings of an ip packet. u will have to remark the packets in checkpoint again for the external router to receive the markings. i guess only cisco asa and netscreen support to retain the markings by the downstream and upstream routers.

however one thing i am not sure that when we are not using qos in checkpoint does it still remove the markings of an ip packet. ???

regards

sebastan
Reply With Quote
  #3 (permalink)  
Old 2008-06-18
steve_mils steve_mils is offline
Junior Member
 
Join Date: 2008-06-11
Posts: 2
Rep Power: 0
steve_mils has an average reputation (10+)
Default Re: Checkpoint and QoS in a cisco network

Hi Sebastan,

I think the thing to do now would be to do some packet sniffing - one capture without QoS enabled on the Checkpoint and another capture after QoS is enabled.

My suspicion is that without QoS enabled the markings are preserved, and with QoS enabled they're remarked.

I'll post here again when I've had the chance to test it...

Thanks, Steve
Reply With Quote
  #4 (permalink)  
Old 2008-06-19
sebastan_bach sebastan_bach is online now
Senior Member
 
Join Date: 2005-10-12
Posts: 315
Rep Power: 3
sebastan_bach has an average reputation (10+)
Send a message via Yahoo to sebastan_bach
Default Re: Checkpoint and QoS in a cisco network

hi steve that;s the correct way to test it. even i was trying to test the same. i will work on it after i get over with vpns.

will surely wait for ur results.

regards

sebastan
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 14:20.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0