> Ruiyuan Jiang wrote:
>
> Hi, all
>
[snip]
>
> We'd like to utilize those 2 T1 link. Our ISP told us that if we can have another IP 
>address then they can route certain Internet traffic such as VPN and mail through 2 
>T1s as default route instead of DS3 and fail over to DS3 in case 2 T1 link is down. I 
>was told by StoneSoft support that StoneBeat support multiple virtual cluster IP 
>addresses lets say I create 10.1.1.13 for external NG interfaces. Check Point support 
>told me that Check Point never tested that way. I have to test it myself. I am think 
>that for site to site VPN, I can work around with Solaris' routing table to route 
>traffic through 2 T1 link for routing (i.e. if the other end of VPN access point is 
>192.1.1.10, I can try "route add host 192.1.1.10 10.1.1.13 1" from Solaris) but not 
>sure about Check Point Firewall-1 NG. Is it possible? How is the rule set about the 
>configuration if I want to route VPN through 2 T1s? Thanks.

I doubt routing things out will be any sort of problem. Check Point and
Stonebeat don't deal with the routing, the underlying OS does, and it sounds
like you know how to get it to do what you want.

I think the trick is going to be getting Check Point to bind its end of
a VPN tunnel (I assume the VPN you speak of is VPN-1 running on the
load-balancing pair?) to a different IP address. Likewise, if your out-
going mail is relayed through the Check Point MTA (incoming wouldn't be
a problem though). I have no idea how to, or if it is possible to, do
either of those. You need to control the _source_ address leaving the
firewall in order to get the ISP to route the return traffic down the
correct pipe from your description of what they've asked for.

Actually, that is not entirely true. Does any outgoing traffic actually
have the firewall's external address now? If not, just use the firewall's
current address as is and route stuff behind it accordingly. However, if
you are one of the unfortunate many doing "hide" NAT, what you may want
to do is the reverse of the previous paragraph. Hide everything behind
another address in the NAT rules, and route the new address through the
DS3, and change the old address, the "real" external address, to go
through the T1 links.

OTOH, if you are not using Check Point as the end of the VPN or as outgoing
an MTA, I don't see how there would be any problems at all.
--
Crist J. Clark                               [EMAIL PROTECTED]
Globalstar Communications                                (408) 933-4387

The information contained in this e-mail message is confidential,
intended only for the use of the individual or entity named above.
If the reader of this e-mail is not the intended recipient, or the
employee or agent responsible to deliver it to the intended recipient,
you are hereby notified that any review, dissemination, distribution or
copying of this communication is strictly prohibited.  If you have
received this e-mail in error, please contact [EMAIL PROTECTED]

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

Reply via email to