[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] Using site to site VPN as backup for dedicated link.



Not a CP solution, but one that worked well in my last job...

The default gateway on each LAN is the WAN router;  the routers on the WAN
use some sort of routing protocol to learn about each other and their route
of last resort is the local FW.  That way, if the WAN goes down, the WAN
routes disappear and the route of last resort takes over.

Julian



|---------+---------------------------------------------->
|         |           Todd Norton                        |
|         |           <[email protected]>       |
|         |           Sent by: Mailing list for          |
|         |           discussion of Firewall-1           |
|         |           <[email protected]|
|         |           kpoint.com>                        |
|         |                                              |
|         |                                              |
|         |           25/09/2002 18:48                   |
|         |           Please respond to Mailing list for |
|         |           discussion of Firewall-1           |
|         |                                              |
|---------+---------------------------------------------->
  >----------------------------------------------------------------------------------------------|
  |                                                                                              |
  |       To:       [email protected]                                 |
  |       cc:                                                                                    |
  |       Subject:  [FW-1] Using site to site VPN as backup for dedicated link.                  |
  >----------------------------------------------------------------------------------------------|




I have 2 sites connected via a dedicated link.  Both of these sites have
separate access to the Internet via. Checkpoint firewalls, which are
centrally managed via the dedicated link.  What I would like to do is, if
the dedicated link between the sites fails, use a site to site VPN tunnel
as
a backup for site to site traffic.  Can I have this done automatically, or
is a manual process needed?  If so, how do I push polices to the firewall
not at same site as the management station if the dedicated link is down?

Any assistance on how to set this up would be greatly appreciated.

thanks,

-tn.

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================

________________________________________________________________________
This e-mail has been scanned for all viruses by Star Internet.







**********************************************************************
Zenith Insurance Management Limited    Registered No. 3805632
Registered @ Zenith House, Market Place, Haywards Heath,
West Sus, RH16 1DB.

NOTICE:
This email and any files transmitted with it are confidential and
intended solely for the use of the individual or entity to whom they
are addressed. If you have received this email in error please notify
the [email protected] and delete the message
and any attachments accompanying it immediately.

**********************************************************************


________________________________________________________________________
This e-mail has been scanned for all viruses by Star Internet.

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================