CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 52 attendees signed up from 14 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-07-31
Fabsta Fabsta is offline
Junior Member
 
Join Date: 2006-07-17
Posts: 10
Rep Power: 0
Fabsta has an average reputation (10+)
Default Mutliple External Interfaces

Peoples - I am having a little problem at the moment. I am currently migrating ISPs and have configured a 2nd external interface on my Checkpoint NGX x45 Crossbeam appliance. It is a clustered interface of which all the rest work perfectly. The problems lies in connecitivty - I can add the intereface perfectly, but then I can connect to it Ok for about 8 or so hrs, and then I cant even get an arp reponse back from it even from the next hop.

The arp table just gives me INCOMPLETE on the router (next hop). Its almost like it doesnt see it at all - I can however ping it from with internal segments, but coming from external, it just doesnt seem to exist. Its like its put the Interface into a type of promiscuos mode for all traffic originating externally.

I have only a 500 node license, and was wondering if I'm allowed 2 external interfaces. Any information would greatly be appreciated. Also any secure client sitre created after I added the 2nd external interface doesnt seem to work at all - I have to delete the 2nd interface and the site can then be connected etc. Secure client issue aside, I really just wanted to know if I can have multiple external interfaces defined - and if so why it deosnt seem to work properly

Kind Regards,
Fab
Reply With Quote
  #2 (permalink)  
Old 2006-09-27
theoracle theoracle is offline
Junior Member
 
Join Date: 2006-09-27
Posts: 12
Rep Power: 0
theoracle has an average reputation (10+)
Default Re: Mutliple External Interfaces

Checkpoint allows multiple external interfaces defined, however your problem may be caused by an ip spoofing issue. After adding the second interface you will need to "disable" ip spoofing detection for this interface in the topology section of the management gui.

theoracle
Reply With Quote
  #3 (permalink)  
Old 2007-03-13
jsalas jsalas is offline
Junior Member
 
Join Date: 2006-11-27
Location: Monterrey, NL, Mexico
Posts: 2
Rep Power: 0
jsalas has an average reputation (10+)
Default Re: Mutliple External Interfaces

Hi,


We have a simmilar problem,

we have 2 Links and we want the first one to send all traffic but VPN Traffic
(this traffic would be sent through the second link).

we are using two default gateways,

the first with a metric of 0
the second with a metric of 100

using Link Selection from checkpoint:

IP Selection by remote peer
Using Ongoing Probing:

Link 1
Link 2

Primary Link 2 ( The VPN preferred link)

Outgoing Route Selection
When Initiating a tunnel: Route based Probing
When responding to a remotely initiated tunnel


so... with the Site 2 site works fine... but with SecureRemote/SEcureClient fails when we try to update topology... because is sending it by the Link 2, with the highest metric of default gateway.

the Site is created pointing to the Link 1 IP, we connect and works fine... but when we make an Update, fails.


Any idea on how to download the topology... or how to make the correct configuration for link selection...??
Reply With Quote
  #4 (permalink)  
Old 2007-03-14
melipla melipla is offline
Senior Member
 
Join Date: 2006-01-25
Posts: 781
Rep Power: 3
melipla has an average reputation (10+)
Default Re: Mutliple External Interfaces

Quote:
Originally Posted by jsalas View Post
or how to make the correct configuration for link selection...??
I don't have answer to your question, but this post may be what you're looking for. It doesn't mention SecureClient per se, but is for link seleciton w/interfaces.
Encrypting From Wrong Interface

Let me know how it progresses!
__________________
Its all in the documentation.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 08:57.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0