No big deal IMHO. Just set up ACL on routers involved, plus the MD5 authentication. Make rule in CP as specific as possible - eg: 179/tcp between this IP and that IP only.. Biggest liability IMHO is using a dynamic routing protocol that can be tampered with (vs using all statics). I'd be more worried about protecting the iBGP session than the FW implications.
hth Joe >>> agentstazi <[EMAIL PROTECTED]> 02/28/02 03:31PM >>> What are some up's and down's to running BGP through FW-1. I will just allow the BGP port number. sr ================================================= To set vacation, Out Of Office, or away messages, send an email to [EMAIL PROTECTED] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [EMAIL PROTECTED] =================================================
