<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Presenting multiple ISP circuits on 1 VS - vRouter? VSLS issue.. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Presenting-multiple-ISP-circuits-on-1-VS-vRouter-VSLS-issue/m-p/98993#M8625</link>
    <description>&lt;P&gt;Just bumping this thread - I presumed there wouldn't be many solutions to this so will close this thread in a few days if no responses.&lt;/P&gt;</description>
    <pubDate>Tue, 13 Oct 2020 15:12:12 GMT</pubDate>
    <dc:creator>JackPrendergast</dc:creator>
    <dc:date>2020-10-13T15:12:12Z</dc:date>
    <item>
      <title>Presenting multiple ISP circuits on 1 VS - vRouter? VSLS issue..</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Presenting-multiple-ISP-circuits-on-1-VS-vRouter-VSLS-issue/m-p/98536#M8624</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Debating over a design snag I have.&lt;/P&gt;&lt;P&gt;The customer has multiple ISP subnets (around 4/5) all presented via the same circuit and tagged with the same VLAN.&lt;/P&gt;&lt;P&gt;I appreciate multiple subnets to 1 VLAN is bad design but thats out of scope for us right now.&lt;/P&gt;&lt;P&gt;I need to present these circuits ideally to 1 VS.&lt;/P&gt;&lt;P&gt;For inbound traffic, there is the possibility I could use proxy arp:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;vSwitch attached to the bond, tagged with the said VLAN above with a wrp link to the VS&lt;/LI&gt;&lt;LI&gt;wrp link on VS has an IP in 1 of the 4/5 subnets above&lt;/LI&gt;&lt;LI&gt;Proxy ARP all the rest of the subnets to the IP assigned above...&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But then you face the issue with outbound traffic and NAT'ing internal servers behind IP addresses that dont exist on the OS i.e there is no route.&lt;/P&gt;&lt;P&gt;vRouters seem like it could solve the issue. Multiple IP's attached to the router and a default route on the VS pointing to the vRouter.&lt;/P&gt;&lt;P&gt;Cluster is currently running VSLS however so that rules out vRouters for now - however cluster could be converted to HA if the&amp;nbsp; vRouters would work effectively.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any design ideas for you guys?&lt;/P&gt;&lt;P&gt;All ideas appreciated. Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2020 08:49:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Presenting-multiple-ISP-circuits-on-1-VS-vRouter-VSLS-issue/m-p/98536#M8624</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2020-10-08T08:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Presenting multiple ISP circuits on 1 VS - vRouter? VSLS issue..</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Presenting-multiple-ISP-circuits-on-1-VS-vRouter-VSLS-issue/m-p/98993#M8625</link>
      <description>&lt;P&gt;Just bumping this thread - I presumed there wouldn't be many solutions to this so will close this thread in a few days if no responses.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 15:12:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Presenting-multiple-ISP-circuits-on-1-VS-vRouter-VSLS-issue/m-p/98993#M8625</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2020-10-13T15:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: Presenting multiple ISP circuits on 1 VS - vRouter? VSLS issue..</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Presenting-multiple-ISP-circuits-on-1-VS-vRouter-VSLS-issue/m-p/99016#M8626</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/40392"&gt;@JackPrendergast&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why not using one of the external subnets as connection to the provider and then let the provider route all traffic for the other subnets to your &amp;nbsp;IP of the VS (no need of a vswitch)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I‘m wondering if you really get all subnets with the same VLAN ID from your provider? This way you have to have one IP of every subnet on your gateway and another IP from the same subnet on the providers router.&lt;/P&gt;
&lt;P&gt;With my description you get all external subnets on your gateway and you can do NAT incoming our outgoing without problems. Normally This should be no problem for your provider to set the needed routes.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2020 19:24:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Presenting-multiple-ISP-circuits-on-1-VS-vRouter-VSLS-issue/m-p/99016#M8626</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-10-13T19:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: Presenting multiple ISP circuits on 1 VS - vRouter? VSLS issue..</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Presenting-multiple-ISP-circuits-on-1-VS-vRouter-VSLS-issue/m-p/103051#M8627</link>
      <description>&lt;P&gt;Hi Wolfgang.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apologies on the late late reply to this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In hindsight you are absolutely correct. The customer I was supporting didnt want to engage with their ISP, so it was up to us to work out a solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In best practise world, your answer would be much better. In the end, we ended up running another connection between the VSX and the switch!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Nov 2020 20:23:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Presenting-multiple-ISP-circuits-on-1-VS-vRouter-VSLS-issue/m-p/103051#M8627</guid>
      <dc:creator>JackPrendergast</dc:creator>
      <dc:date>2020-11-23T20:23:49Z</dc:date>
    </item>
  </channel>
</rss>

