<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BGP routing through R80.10 gateway and packet inspection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routing-through-R80-10-gateway-and-packet-inspection/m-p/76603#M11506</link>
    <description>&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;thanks for your swift reply!&lt;/P&gt;&lt;P&gt;This is what I thought but wanted to make sure before implementing the solution.&lt;/P&gt;&lt;P&gt;I had also read about the impact on the ebgp multi-hop value.&lt;/P&gt;&lt;P&gt;Thanks for confirming.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Feb 2020 15:39:14 GMT</pubDate>
    <dc:creator>athomson</dc:creator>
    <dc:date>2020-02-27T15:39:14Z</dc:date>
    <item>
      <title>BGP routing through R80.10 gateway and packet inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routing-through-R80-10-gateway-and-packet-inspection/m-p/76487#M11504</link>
      <description>&lt;P&gt;We are currently looking to locate a VPN router within a DMZ and to establish a BGP session to an internal router that sits behind a Checkpoint R80.10 gateway. Other than inspecting the BGP session packets would the firewall also inspect the packets between the two hosts as shown in the diagram? For example, if host A was attempting to SSH to host B would the firewall block that connectivity unless a firewall rule was configured to allow it?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 16:13:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routing-through-R80-10-gateway-and-packet-inspection/m-p/76487#M11504</guid>
      <dc:creator>athomson</dc:creator>
      <dc:date>2020-02-26T16:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: BGP routing through R80.10 gateway and packet inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routing-through-R80-10-gateway-and-packet-inspection/m-p/76497#M11505</link>
      <description>&lt;P&gt;Sure, traffic between host A and B would still have to cross the firewall. BGP isn't a tunnel its just a distributed route database application basically.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think a problem you should keep in mind is the firewall will need to know what networks exist behind the VPN router and topology will need to be updated to reflect this.&lt;/P&gt;&lt;P&gt;In addition assuming the BGP peers on on different ASes you'll need to tweak the BGP conf with ebgp multi-hop and possibly next hop self. You'll need the multi hop because ebgp defaults to a IP TTL of 1. With ebgp multihop 2 it becomes 2 and you'll be able to reach the router that is one hop away.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 19:23:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routing-through-R80-10-gateway-and-packet-inspection/m-p/76497#M11505</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-02-26T19:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: BGP routing through R80.10 gateway and packet inspection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routing-through-R80-10-gateway-and-packet-inspection/m-p/76603#M11506</link>
      <description>&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;thanks for your swift reply!&lt;/P&gt;&lt;P&gt;This is what I thought but wanted to make sure before implementing the solution.&lt;/P&gt;&lt;P&gt;I had also read about the impact on the ebgp multi-hop value.&lt;/P&gt;&lt;P&gt;Thanks for confirming.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 15:39:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/BGP-routing-through-R80-10-gateway-and-packet-inspection/m-p/76603#M11506</guid>
      <dc:creator>athomson</dc:creator>
      <dc:date>2020-02-27T15:39:14Z</dc:date>
    </item>
  </channel>
</rss>

