CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Topology Issues
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-11-20
Junior Member
 
Join Date: 2006-12-19
Posts: 3
Rep Power: 0
watcher60 has an average reputation (10+)
Default Adding second internet feed---any ideas??

my company is trying to introduce a second internet feed (ADSL feed) to the nokia ipso firewall-1 (NG+AI) for outbound traffic but still want to route VPN traffic down the existing lease line. The ADSL feed is connected to a ADSL router which is perfoming hider NAT which the firewall-1 box is directly connected to.

As we have VPN's terminated on the existing external interface (193.132.132.2) & externally NAT'd IP's on the 193.132.132.0/24 range we still require these to remain in place. I was hoping that by changing the default route on the fw-1 box to the adsl router (192.168.253.146) and adding static routes for the VPN traffic & relevant remote vpn gateways this would allow us to use the ADSL feed for outbound internet traffic, VPN traffic down the existing lease line feed & that externally NAT'd machines would still answer inbound requests on their nat'd IP (which is on the existing lease line).

Unfortunately while the VPN's still worked and machines in the LAN outbound connections were routed down the ADSL feed, inbound requests to NAT'd IP's in the 193.132.132.0/24 range failed though I could see them being accepted inbound. I believe that this is due to the return path of the packets going out of the default route ADSL feed rather than the existing lease line feed.
The only way I could see of overcoming this would be to create 2 seperate routing tables on the fw-1 box, one with the ADSL feed, one with the Verizion feed, each with a seperate interface/IP in the LAN. Externally NAT'd machines would have to be pointed at the router instance with the Verizion feed , all other at the one with the ADSL feed. Then on the routing instance with the ADSL feed have a route pointing all VPN traffic at the other routing instance.

I don't believe you can have 2 routing tables on a ipso box - can anyone think of a way to do this all in the fw-1 box? -thanks and sorry for the long post :)
Reply With Quote
  #2 (permalink)  
Old 2007-11-20
Senior Member
 
Join Date: 2007-06-04
Posts: 1,071
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Adding second internet feed---any ideas??

You have correctly identified the problem. For VPN's you could add static routes going via the lease line to the VPN gateways, however unless you know the destinations then will still leave you with problems.

ISP Redundancy is the answer.

Create the existing line as the primary and the ADSL as secondary and then use load sharing.

This will send all static NAT traffic down existing primary line, and load balance hide traffic between the ADSL and existing line. Add static routes for the VPN's via the lease line.

If you keep your DNS the same then inbound connections will only arrive on the existing lease line.
Reply With Quote
  #3 (permalink)  
Old 2007-11-21
Junior Member
 
Join Date: 2006-12-19
Posts: 3
Rep Power: 0
watcher60 has an average reputation (10+)
Default Re: Adding second internet feed---any ideas??

I've just read this is the support notes for R55:

92) ISP Redundancy is not supported with FloodGate-1.

I am currently using FloodGate - do you know if later versions of fw-1 have worked around this?
Reply With Quote
  #4 (permalink)  
Old 2007-11-21
Senior Member
 
Join Date: 2007-06-04
Posts: 1,071
Rep Power: 3
mcnallym has an average reputation (10+)
Default Re: Adding second internet feed---any ideas??

If you are still on R55 then ISP Redundancy doesn't work on Nokia's anyway.

I have implemented R62 and Floodgate ISP Redundancy, so has been fixed.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:14.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0