Without this becaming a logistics nightmare,...Checkpoint doesn't like asymetric routing as been said below... You have to know the "source IP address" of the incoming traffic so it can be send out the same firewall (or same interface) on the gateway that it came in....with the appropriate NAT on the way out. That also means....a lot of MANUAL NATs If the traffic is limited....you may be able get away by adding a lot of STATIC routes at the gateways.... If traffic is unlimited,,,then you need a different solution....
--- On Mon, 2/8/10, pkc_mls <[email protected]> wrote: From: pkc_mls <[email protected]> Subject: Re: [FW-1] Checkpoint routing and NAT To: [email protected] Date: Monday, February 8, 2010, 2:39 AM Peter Addy a écrit : > Hi > Does anyone have an idea on this one, thanks gain Hi, Checkpoint doesn't like asymetric routing. the best is to use the same firewalls for both directions. If needed, NAT the source on the ng fp3 to make sure the return packets will also go through this device. Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] ================================================= Scanned by Check Point Total Security Gateway. ================================================= To set vacation, Out-Of-Office, or away messages, send an email to [email protected] in the BODY of the email add: set fw-1-mailinglist nomail ================================================= To unsubscribe from this mailing list, please see the instructions at http://www.checkpoint.com/services/mailing.html ================================================= If you have any questions on how to change your subscription options, email [email protected] =================================================
