CPUG: The Check Point User Group

Resources for the Check Point Community, by the Check Point Community.


Tim Hall has done it yet again - That's right, the 3rd edition is here!
You can read his announcement post here.
It's a massive upgrade focusing on current versions, and well worth checking out. -E

 

Results 1 to 11 of 11

Thread: What about advanced routing then ..... Help!!

  1. #1
    Join Date
    2008-10-23
    Posts
    8
    Rep Power
    0

    Default What about advanced routing then ..... Help!!

    I hoping someone can help.

    I am running R65 Splat 2.6 on ESX 3i version 3.5 and it runs fine. BUT splat 2.6 is not supported on a virtual platform. I've installed the correct VE on splat 2.4 on one of our sites however this site doesn't require any routing entries or OSPF.

    However, I now need to install a version that does support dynamic routing eg OSPF I know that I can update a file to keep the routes alive after a reboot but nothing to enable the advanced routing protocols?

    I would expect the simple answer is to install splat 2.4!!

    List of comparisons between VE and standard version


    Please can anyone advise?

  2. #2
    Join Date
    2007-07-16
    Location
    a land down under!
    Posts
    2,015
    Rep Power
    15

    Default Re: What about advanced routing then ..... Help!!

    SecurePlatform PRO is supported in the 2.4 kernel. At the command prompt, type in the command "pro enable" then reboot. Whether it's supported in VE is another question.

  3. #3
    Join Date
    2008-10-23
    Posts
    8
    Rep Power
    0

    Default Re: What about advanced routing then ..... Help!!

    Many thanks for that, I don't see any difference at the moment but then again I've not conencted fw to a SmartCenter.

    I'm just configuring a few boxes in my virtual lab environment to test.

    Will let you know the outcome.

  4. #4
    Join Date
    2008-10-23
    Posts
    8
    Rep Power
    0

    Default Re: What about advanced routing then ..... Help!!

    Quote Originally Posted by Thorpuse View Post
    SecurePlatform PRO is supported in the 2.4 kernel. At the command prompt, type in the command "pro enable" then reboot. Whether it's supported in VE is another question.
    Thanks again Thorpuse, Lab tests worked and just received confirmation from Check Point, VE is supported in SPLAT PRO format and "enable pro" is the way to go.

    Check Point took their time in responding!

    Thanks again...

  5. #5
    Join Date
    2007-07-16
    Location
    a land down under!
    Posts
    2,015
    Rep Power
    15

    Default Re: What about advanced routing then ..... Help!!

    No worries - I received confirmation of exactly the same thing today as well.

    Be interested to know if Vmotion works with it? CP claims it does, if you have the chance to test it let us all know.

  6. #6
    Join Date
    2007-06-04
    Posts
    3,314
    Rep Power
    17

    Default Re: What about advanced routing then ..... Help!!

    They have updated the VE so that supports VMTools. The initial release didn't support VMTools, so didn't support vmotion.

  7. #7
    Join Date
    2006-07-04
    Posts
    14
    Rep Power
    0

    Default Re: What about advanced routing then ..... Help!!

    Hi mcnallym,

    I have just downloaded the latest release of NGX R65 VE and the vmware tools are not installed. WHen I try to install tem it looks like Perl is requried.
    Also, I cannot find on the checkpoint site anywhere where they say vmtools is supported.
    Can you clarify a bit?

    Thanks,

    jeroeJ

  8. #8
    Join Date
    2006-06-12
    Posts
    23
    Rep Power
    0

    Default Re: What about advanced routing then ..... Help!!

    You don't strictly need VMware Tools for vmotion... it's only a warning.
    ---
    Tom Rowan
    CCSA, CCSE, CCSE+
    VCP4, VCP3, VCI
    MBCS CITP

  9. #9
    Join Date
    2009-11-27
    Posts
    18
    Rep Power
    0

    Default Re: What about advanced routing then ..... Help!!

    hi,

    SecurePlatform Pro will work with VPN-1 VE and I am using it in my infrastructure. Regarding the support, well to be honest I have raised several cases and the support team always resolved the problem. I have spoken to several guys from Checkpoint and they have said that it will run but if new issues are present (ones which are not registered on Secure Knowledge) then you do not have support.

    I am running SecurePlatform Pro in ClusterXL environment with OSPF (Load-Sharing multicast) and iBGP (New HA mode).

    Regarding vMotion, it will work only if you are using a single box for everything (SmartCenter and Security Gateway). In all other scenarios vMotion is not supported, this can cause issues in clustered environments.

  10. #10
    Join Date
    2008-02-20
    Location
    New Zealand
    Posts
    22
    Rep Power
    0

    Default Re: What about advanced routing then ..... Help!!

    i talked to our local VM SE and he said checkpoint werent even keen to do a demo for them :-)

    should download this and have a play, gotta be better than vshield!!

    cheers,
    Doing the needfull!

  11. #11
    Join Date
    2009-11-27
    Posts
    18
    Rep Power
    0

    Default Re: What about advanced routing then ..... Help!!

    Hi,

    Well I have participated in the EA and its a lot better than vShield zones. I have deployed it in the Avatar mode and L3 mode. Avatar allows you to inspect inter-vm traffic in the same subnet with IPS signatures and other stuff. I would like to have DLP embedded (IMO).
    Predrag Petrovic
    CCSE+, CCSE R70, VCP VAC, CCSP, CCDA, MCSE:Sec

Similar Threads

  1. R70 IPS Lite vs IPS advanced???
    By ChadB in forum IPS-1
    Replies: 7
    Last Post: 2009-08-24, 22:51
  2. Advanced upgrade R6X to R65 - if it fails
    By varera in forum Installing And Upgrading
    Replies: 1
    Last Post: 2008-12-01, 03:12
  3. ClusterXL HA and Advanced Routing Problem!!!
    By crispbee in forum Clustering (Security Gateway HA and ClusterXL)
    Replies: 9
    Last Post: 2008-05-30, 03:13
  4. Basic and Advanced
    By derspot in forum Feedback To Check Point: Suggestions And Requests
    Replies: 0
    Last Post: 2007-01-01, 14:32
  5. Advanced NAT question
    By l0wkey in forum NAT (Network Address Translation)
    Replies: 1
    Last Post: 2006-08-02, 16:02

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •