<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use two internet links in a Virtual System using a virtual router in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Use-two-internet-links-in-a-Virtual-System-using-a-virtual/m-p/59451#M12011</link>
    <description>&lt;P&gt;Julio,&lt;/P&gt;&lt;P&gt;if you want to &amp;nbsp;use a virtual-router you have to dig a little bit deeper how it works and some limitation.&lt;/P&gt;&lt;P&gt;PBR with virtual-router in a VSX environment does not fully support all normal PBR features.&lt;/P&gt;&lt;P&gt;some things to decide:&lt;/P&gt;&lt;P&gt;- virtual-router is only supported on VSX HA, no VSLS&lt;/P&gt;&lt;P&gt;- PBR routes are only possible for IP-subnets, not for TCP/UDP-services ( this is available in one of the newest or future releases, I’m not sure at the moment which)&lt;/P&gt;&lt;P&gt;- PBR routes can have only other virtual-systems as gateway, no gateway IP address possible&lt;/P&gt;&lt;P&gt;- you can‘t configure firewalls or NAT rules on a virtual-router, it‘s only a router&lt;/P&gt;&lt;P&gt;- you can attach a virtual-router unnumbered to the virtual systems, you don‘t need to have a network segment or virtual switch for these connection&lt;/P&gt;&lt;P&gt;We had a customer with a similar &amp;nbsp;requirement, we used the virtual-router and PBR. We had one VS as main firewall, and two other VS with the ISP connections. VS1 with ISP1 and VS2 with ISP2. They all are connected via the virtual-router.&lt;/P&gt;&lt;P&gt;The main Firewall has a default-Route pointing to the virtual-router and on the virtual-router there are PBR-routes sending packets out to VS1 or VS2 (ISP1 and ISP2) regarding of the source IP subnets.&lt;/P&gt;&lt;P&gt;On the external VS1 and VS2 we have only limited firewall rules. They are used mainly for NAT to the ISPs and VPN entry point. Using of these scenario has some overhead and has to be really good developed before going in production.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The requirement for the two external VS is the limitation of not having the possibility to define an IP-address as gateway &amp;nbsp;in a PBR-route.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
    <pubDate>Thu, 01 Aug 2019 19:47:56 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2019-08-01T19:47:56Z</dc:date>
    <item>
      <title>Use two internet links in a Virtual System using a virtual router</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Use-two-internet-links-in-a-Virtual-System-using-a-virtual/m-p/59445#M12007</link>
      <description>&lt;P&gt;I have a VSX cluster, with two VS, one VS as internal firewall and another VS as external firewall.&lt;/P&gt;&lt;P&gt;In the external VS I need to connect two internet links, although ISP redundancy is not supported for VSX, I would like to use my second internet link using PBR, for which I must configure a virtual router that receives both public interfaces and configure the advance routing for the VR. I would create a new segment between the VR and the external VS.&lt;/P&gt;&lt;P&gt;Is this possible??&lt;/P&gt;&lt;P&gt;Can I configure the NATs that I currently have in the external VS in the new VR?&lt;/P&gt;&lt;P&gt;If I can configure NATs on the virtual router, can I do a NAT and keep the S2S VPNs that I have on the external VS?&lt;/P&gt;&lt;P&gt;Your help please&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 16:54:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Use-two-internet-links-in-a-Virtual-System-using-a-virtual/m-p/59445#M12007</guid>
      <dc:creator>Julio_Rugel</dc:creator>
      <dc:date>2019-08-01T16:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Use two internet links in a Virtual System using a virtual router</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Use-two-internet-links-in-a-Virtual-System-using-a-virtual/m-p/59451#M12011</link>
      <description>&lt;P&gt;Julio,&lt;/P&gt;&lt;P&gt;if you want to &amp;nbsp;use a virtual-router you have to dig a little bit deeper how it works and some limitation.&lt;/P&gt;&lt;P&gt;PBR with virtual-router in a VSX environment does not fully support all normal PBR features.&lt;/P&gt;&lt;P&gt;some things to decide:&lt;/P&gt;&lt;P&gt;- virtual-router is only supported on VSX HA, no VSLS&lt;/P&gt;&lt;P&gt;- PBR routes are only possible for IP-subnets, not for TCP/UDP-services ( this is available in one of the newest or future releases, I’m not sure at the moment which)&lt;/P&gt;&lt;P&gt;- PBR routes can have only other virtual-systems as gateway, no gateway IP address possible&lt;/P&gt;&lt;P&gt;- you can‘t configure firewalls or NAT rules on a virtual-router, it‘s only a router&lt;/P&gt;&lt;P&gt;- you can attach a virtual-router unnumbered to the virtual systems, you don‘t need to have a network segment or virtual switch for these connection&lt;/P&gt;&lt;P&gt;We had a customer with a similar &amp;nbsp;requirement, we used the virtual-router and PBR. We had one VS as main firewall, and two other VS with the ISP connections. VS1 with ISP1 and VS2 with ISP2. They all are connected via the virtual-router.&lt;/P&gt;&lt;P&gt;The main Firewall has a default-Route pointing to the virtual-router and on the virtual-router there are PBR-routes sending packets out to VS1 or VS2 (ISP1 and ISP2) regarding of the source IP subnets.&lt;/P&gt;&lt;P&gt;On the external VS1 and VS2 we have only limited firewall rules. They are used mainly for NAT to the ISPs and VPN entry point. Using of these scenario has some overhead and has to be really good developed before going in production.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The requirement for the two external VS is the limitation of not having the possibility to define an IP-address as gateway &amp;nbsp;in a PBR-route.&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 19:47:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Use-two-internet-links-in-a-Virtual-System-using-a-virtual/m-p/59451#M12011</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-08-01T19:47:56Z</dc:date>
    </item>
  </channel>
</rss>

