CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-14
Member
 
Join Date: 2006-06-06
Posts: 72
Rep Power: 3
lowfell has an average reputation (10+)
Default Can i go in and out the same interface? on R55?

I'm using R55 as my Lan gateway. lets say this has an inside ip address of
192.168.1.254/24

ALL my lan hosts have the Checkpoint as their Gateway. 192.168.1.254/24

I also have a none Checkpoint device on the same network that terminates a site to site vpn, lets say
its ip address is 192.168.1.252/24


1. CAN I PUT A ROUTE ON THE CHECKPOINT TO POINT TO THE VPN DEVICE FOR TRAFFIC TO AND FROM THE REMOTE ENCRYPTION DOMAIN AND CREATE FIREWALL RULES FOR THIS? OR, IS THIS NOT POSSIBLE BECAUSE I'LL BE GOING IN AND OUT THE SAME INTERFACE???
Reply With Quote
  #2 (permalink)  
Old 2007-09-14
Member
 
Join Date: 2006-11-03
Posts: 34
Rep Power: 0
inetd has an average reputation (10+)
Default Re: Can i go in and out the same interface? on R55?

I have never tried but I would use dhcp option 121. Pass a static-route via dhcp to the clients.
Reply With Quote
  #3 (permalink)  
Old 2007-09-16
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Can i go in and out the same interface? on R55?

It should work but you may have to allow ICMP Redirects.

I've tried it myself and it didn't work, but I also didn't debug it because for the one machine that needed the route it was just as fast to put in the static.

please let us know what you find out.
Reply With Quote
  #4 (permalink)  
Old 2007-09-17
Senior Member
 
Join Date: 2006-09-26
Posts: 821
Rep Power: 3
cciesec2006 has an average reputation (10+)
Default Re: Can i go in and out the same interface? on R55?

I tested it and it works for me, like this:

R1---FW1-----Internet----R2.

Lan-2-Lan vpn between R1 and R2. FW internal ip address
is 192.168.1.254/24. R1 has an ip address of 192.168.2.251/24.

it will work just fine. Remember, whatever the local encryption
domain you have on R1, FW-1 knows nothing about because
once the traffics leave R1, it will be encrypted anyway. FW-1
will see nothing but ike and esp traffics, or udp-4500 if you're
doing nat-traversal, with ip address of 192.168.1.252/24.
You don't need any static routes at all. You just need default
route on R1 to point to FW-1. Unless you're doing a one-arm
routing on the Cisco router, then the configuration will be a
little different. In that case, you need to have static-route
on the firewall to point remote encryption domain with
the next-hop to be the router.

HTH
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:10.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0