Without this becaming a logistics nightmare,...Checkpoint doesn't like 
asymetric routing
as been said below...
 
You have to know the "source IP address" of the incoming traffic so it can be 
send out the same firewall (or same interface) on the  gateway that it came 
in....with the appropriate NAT on the way out.
That also means....a lot of MANUAL NATs
 
If the traffic is limited....you may be able get away by adding a lot of STATIC 
routes at the gateways....
 
If traffic is unlimited,,,then you need a different solution....
 


--- On Mon, 2/8/10, pkc_mls <[email protected]> wrote:


From: pkc_mls <[email protected]>
Subject: Re: [FW-1] Checkpoint routing and NAT
To: [email protected]
Date: Monday, February 8, 2010, 2:39 AM


Peter Addy a écrit :
> Hi 
> Does anyone have an idea on this one, thanks gain

Hi,

Checkpoint doesn't like asymetric routing.
the best is to use the same firewalls for both directions.
If needed, NAT the source on the ng fp3 to make sure the return packets
will also go through this device.



Scanned by Check Point Total Security Gateway.

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================






Scanned by Check Point Total Security Gateway.


=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================

Reply via email to