Hi,

First, read the chapter "Site-to-Site VPN"->"Route Based VPN"->"VTIs in a 
Clustered Environment", on the CheckPoint_R65_VPN_AdminGuide.
Step-by-Step example configuration provided.

Best Regards

-----Original Message-----
From: Mailing list for discussion of Firewall-1 [mailto:[EMAIL PROTECTED] On 
Behalf Of Alan Choyna
Sent: sábado, 5 de Janeiro de 2008 22:09
To: [email protected]
Subject: Re: [FW-1] Implementing a point to point connection between 2 
Checkpoint R65 firewall clusters

Sorry for not being clearer, Yes we do have switches at each end, 
otherwise we could not have the clustered gateways at each location.

What I would like to do is leave the routing out of the switches and 
have it on the firewalls if that's possible.

For instance, l could just set up the interface on the Cluser A 
firewalls to have the 192.168.6 - 10 networks in a network group object 
that would be used on the gateway interface properties tab, under the 
topology section. This would route all traffic to those network through 
to the other gateway via the point to point connection.

My questions are in regards to the configuration at the Cluster B 
gateways to route the traffic back from the .5, .6, etc networks back 
through the point to point interface. What do l need to do to make that 
happen?

Thanks,

Alan

Hugo van der Kooij wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> Alan Choyna wrote:
>   
>> Hey Guru's,
>>
>> I've been working with checkpoint for years but have never configured a
>> point to point connection between 2 checkpoint firewalls. We wish to
>> connect the ethernet drops directly to the firewalls (bypassing any need
>> for intermediary switches).
>>
>> Both Firewall clusters are running R65.
>>
>> We currently have a VPN tunnel providing this connectivity via our
>> external WAN connection, and now wish to route via the Point to point.
>>
>> Behind firewall cluster A we have the 192.168.1.0 thru 192.168.5
>> networks (each on a separate DMZ firewall port), and behind firewall
>> cluster B we have the 192.168.6.0 thru 192.168.10 networks (each on a
>> separate DMZ firewall port).
>>
>> How do l configure the Firewall ports at each end of the firewall? and
>> how do l configure the routes and rules to route the traffic correctly
>> between the 2 firewalls?
>>     
>
> What do you care if the next hop is a Check Point firewall doing
> routing, or if it is some other router? IP routing is IP routing.
>
> The only care is that need to make sure that each cluster uses an unique
> identifier. read all about the mac magic (or was it magic mac?) in the
> knowledgebase.
>
> I fail to see how you can make clustering work without the use of
> properly connected L2 switches.
>
> I suggest you take pen and paper and make yourself a drawing of it and
> follow the path for each variable. So think what happens if you take
> cluster members out of the drawing and see if it still works. I think
> you will see quite a bit of problems if you use direct connections
> without a switch in between.
>
> Hugo.
>
> - --
> [EMAIL PROTECTED]               http://hugo.vanderkooij.org/
> PGP/GPG? Use: http://hugo.vanderkooij.org/0x58F19981.asc
>
>       A: Yes.
>       >Q: Are you sure?
>       >>A: Because it reverses the logical flow of conversation.
>       >>>Q: Why is top posting frowned upon?
>
> Bored? Click on http://spamornot.org/ and rate those images.
>
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.7 (GNU/Linux)
>
> iD8DBQFHfdr2BvzDRVjxmYERApLlAJ9cHLgZVItkr5WDXBJ2S1BO6TBuPwCff0HO
> fab6MQXRZQBIuVD+KEnn46A=
> =rAlM
> -----END PGP SIGNATURE-----
>
> Scanned by Check Point Total Security Gateway.
>
> =================================================
> To set vacation, Out-Of-Office, or away messages,
> send an email to [EMAIL PROTECTED]
> in the BODY of the email add:
> set fw-1-mailinglist nomail
> =================================================
> To unsubscribe from this mailing list,
> please see the instructions at
> http://www.checkpoint.com/services/mailing.html
> =================================================
> If you have any questions on how to change your
> subscription options, email
> [EMAIL PROTECTED]
> =================================================
>
>   

Scanned by Check Point Total Security Gateway.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================
###############################################################################################
Verificado por MailMarshal

Marshal é uma solução de segurança de conteúdos, com capacidade de anti-virus, 
anti-spam, anti-phishing, anti-spyware, análise de imagems, DHA e DoS ao nível 
da gateway.

Para obter mais informações e uma versão totalmente funcional com validade para 
30 dias visite
http://www.tecnidata.pt/Solucoes/Solucoes+Tecnologicas/SegurancaTI/Seguranca+de+Conteudos.htm

Se pretender uma demo deste produto contacte em Portugal [EMAIL PROTECTED]

###############################################################################################

Scanned by Check Point Total Security Gateway.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to