CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have 72 attendees signed up from 20 countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > High-End Security > VPN-1 VSX
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-20
eduardw eduardw is offline
Member
 
Join Date: 2007-08-04
Posts: 53
Rep Power: 2
eduardw has an average reputation (10+)
Default How to add multiple routes on a VSX firewall cluster?

We are in the progress of migrating our firewalls to VSX clusters on HP hardware.
But on many of the firewalls we have, have more then 100 static routes some have even more the 500.
I know you can ad these route individual by using the GUI. But this is a very time consuming and unreliable process. Is there a proven method of adding multiple routes on the command line of the virtual system (firewall).

Most of our current firewalls are running on sun Solaris a few on Secure platform.


Kind Regards


Eduard


The Netherlands
Reply With Quote
  #2 (permalink)  
Old 2007-12-13
Routerkid1 Routerkid1 is offline
Senior Member
 
Join Date: 2006-12-16
Posts: 131
Rep Power: 2
Routerkid1 has an average reputation (10+)
Default Re: How to ad multiple routes on a VSX firewall cluster?

route add command but it will not survive a reboot. You will need to use sysconfig.
Reply With Quote
  #3 (permalink)  
Old 2007-12-15
eduardw eduardw is offline
Member
 
Join Date: 2007-08-04
Posts: 53
Rep Power: 2
eduardw has an average reputation (10+)
Default Re: How to ad multiple routes on a VSX firewall cluster?

Thanks, we are working hard to get the number of routes down.
The only correct way for VSX is adding them in the policy. Checkpoint has told us that they will working on a feature so we can add rules from files. But not before Q3 2008 .
In the mean while we have migrate about 30 firewalls to VSX, with a average down time of under 80 seconds. But adding the routes takes al lot of time about 45tot 60seconds a route. So this is still a very time consuming job. We have not yet tried to migrate the firewalls with the large route tables 600+.

I hope checkpoint will have the imports routes from file feature a lot sooner. Because I don’t want to spend my weekends the next year for migrating firewalls with large route tables.


Kind Regards
Eduard
Reply With Quote
  #4 (permalink)  
Old 2007-12-19
lunatrick lunatrick is offline
Member
 
Join Date: 2007-02-26
Posts: 33
Rep Power: 0
lunatrick has an average reputation (10+)
Default Re: How to ad multiple routes on a VSX firewall cluster?

I have seen some kind of visual basic script run to add a large number of routes in one go - but I don't have the script unfortunately....anyway just a blunt tool to speed up the data entry....
Reply With Quote
  #5 (permalink)  
Old 2008-04-11
eduardw eduardw is offline
Member
 
Join Date: 2007-08-04
Posts: 53
Rep Power: 2
eduardw has an average reputation (10+)
Default Re: How to ad multiple routes on a VSX firewall cluster?

Last week I’ve spoken to our checkpoint sales rep.
He told us that they put this feature high on the list for enhancements request. That’s great but no date yet.
I would love to see a offline configuration tool for creating virtual system off course with the option of adding routes by importing them form a csv file.

Eduard
The Netherlands
Reply With Quote
  #6 (permalink)  
Old 2008-04-29
Eaulivier Eaulivier is online now
Junior Member
 
Join Date: 2006-10-06
Location: Belgium
Posts: 9
Rep Power: 0
Eaulivier has an average reputation (10+)
Default Re: How to ad multiple routes on a VSX firewall cluster?

Quote:
Originally Posted by eduardw View Post
Last week I’ve spoken to our checkpoint sales rep.
He told us that they put this feature high on the list for enhancements request. That’s great but no date yet.
I would love to see a offline configuration tool for creating virtual system off course with the option of adding routes by importing them form a csv file.

Eduard
The Netherlands
Hello Eduard,

You can use the CLI commando route add and at the end have

save_route --save

To effectively save your static routes that will survive a reboot !

With kind regards,

Olivier
Reply With Quote
  #7 (permalink)  
Old 2008-04-29
abusharif abusharif is offline
Senior Member
 
Join Date: 2006-04-27
Location: Twillight zone
Posts: 445
Rep Power: 3
abusharif has an average reputation (10+)
Default Re: How to add multiple routes on a VSX firewall cluster?

you can also script it directly to the config file (/etc/sysconfig/netconf.c)
Reply With Quote
  #8 (permalink)  
Old 2008-05-04
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,632
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: How to add multiple routes on a VSX firewall cluster?

This is true on standard SPLAT, it is not the case for a VS or VR on VSX.
Open a support call and or really bug your SE, I would bet there is an unsupported script floating around somewhere to do just this.
Reply With Quote
  #9 (permalink)  
Old 2008-05-04
eduardw eduardw is offline
Member
 
Join Date: 2007-08-04
Posts: 53
Rep Power: 2
eduardw has an average reputation (10+)
Default Re: How to add multiple routes on a VSX firewall cluster?

Thanks all, because I’ve still not find a solution to our problem, we are going to migrate to a temporary solution before we migrate the 2 firewalls to vsx.
The routes on the firewalls will be migrated to 2 standalone cisco routes to handle the route table. The firewalls will get a default route to one of these routers.
When checkpoint has figured it out to at bulk routes and away to sort them in the topology tab then we probably migrate the routes back to the vsx firewalls.

Regards

Eduard
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 07:06.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0