CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > VPN's (Virtual Private Networks)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-02-23
Member
 
Join Date: 2006-01-07
Posts: 32
Rep Power: 0
philofish has an average reputation (10+)
Default Last question on traditional VPN's then i am outta here ;)

Can someone just clarify whether when in traditional mode there is usually 1 management server managing multiple dstributed firewalls?

Yes or no?

and i assume that If this is the case then [silly question] the management server could be on the same subnet as gateway1 BUT on a completely different subnet of that of gateway2? that is correct - yes?

If thats the case then an outbound rule must be in place for me to manage the remote gateway [gateway2] on gateway1, i.e. for SIC connections otherwise i would see SYN_SENT on my management server - and logs in smart view.

Thanks

Last edited by philofish; 2006-02-23 at 02:46.
Reply With Quote
  #2 (permalink)  
Old 2006-02-26
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,670
Rep Power: 5
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: Last question on traditional VPN's then i am outta here ;)

VPN mode is not relivent here. If a SC is managing a gateway outside of a firewall, the distant gateway needs to be able to contact the SC. This usualy requires setting up a static NAT for the SC. The implied rules should take care of the rest. The only thing to remember here is that after you create the distant firewall object, you need to install the policy to the local gateway before you can estiblish SIC.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 00:36.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0