Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Redundant firewall / network design question

Status
Not open for further replies.

dieselhead

Technical User
Dec 10, 2002
1
GB
I am fairly new to firewalling. My background is OSPF / Integrated IS-IS routing.

In my current company they use Nokia firewalls running Checkpoint Firewall VPN.

I can't figure out how to get redundant routes through them if they are state aware.

I could enable OSPF on the firewalls, or run OSPF virtual adjacencies through them, but with OSPF going off to some edge router that connects to the internet then I can't guarantee that a TCP session will not go out through one site or ISP and then come back through the other. Therefore I get an assymetric traffic flow and the session aware rules dump the session.

I can't easily sync two firewalls that are on different sites in different parts of the country.

The only solution appears to be to funnel all the traffic through one sire and run them through a firewall pair with a VRRP address.

This isn't quite the level of redundancy that I'm looking for.

How do I solve this?

 
2 solutions: We use Radware Linkproofs, connecting 2 Nokias to 2 ISPs. You then setup the 2 nokias as a cluster, with a VIP on the Radwares.

Option 2 is new, and I haven't tested: supposedly, NG fp3 with the new IPSO (3.6?) cures this problem, no hardware to purchase. Again, untried.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top