<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Asymmetric routing with checkpoint inline. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Asymmetric-routing-with-checkpoint-inline/m-p/49983#M9825</link>
    <description>&lt;P&gt;Maybe dynamic routing protocols can achieve your requirement....&lt;/P&gt;&lt;P&gt;CP15600 cluster points the default static route to internet router, then redistribute to ospf instance, then core switch would learn this default information, the client traffic will then go through core switch-&amp;gt;CP15600 cluster-&amp;gt;internet router, as for the return traffic, because internet router will learn all the vlans information from core switch, so return traffic would be internet routers-&amp;gt;core switch-&amp;gt;user subnets.&lt;/P&gt;&lt;P&gt;Or you may simply use PBR on internet routers to force return traffic go through core switches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 06 Apr 2019 11:34:40 GMT</pubDate>
    <dc:creator>Neville_Kuo</dc:creator>
    <dc:date>2019-04-06T11:34:40Z</dc:date>
    <item>
      <title>Asymmetric routing with checkpoint inline.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Asymmetric-routing-with-checkpoint-inline/m-p/49979#M9824</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="design.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/672i46751E2F3FB8788C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="design.png" alt="design.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;customer is a TELCO/ISP and has procured checkpoint 15600 cluster. firewall will be used to filter customers traffic and apply quality of service on them. customer wants the firewall to support asymmetric traffic. only the outgoing connections will go through the firewall and return traffic will be directly routed to the core switch from the router. i have attached the design.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;default gateway of core switch is firewall&lt;/P&gt;
&lt;P&gt;on the router the return traffic is routed back to the core switch.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;is there any way we can make it work. please confirm&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2019 10:35:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Asymmetric-routing-with-checkpoint-inline/m-p/49979#M9824</guid>
      <dc:creator>Sameer_Basha</dc:creator>
      <dc:date>2019-04-06T10:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: Asymmetric routing with checkpoint inline.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Asymmetric-routing-with-checkpoint-inline/m-p/49983#M9825</link>
      <description>&lt;P&gt;Maybe dynamic routing protocols can achieve your requirement....&lt;/P&gt;&lt;P&gt;CP15600 cluster points the default static route to internet router, then redistribute to ospf instance, then core switch would learn this default information, the client traffic will then go through core switch-&amp;gt;CP15600 cluster-&amp;gt;internet router, as for the return traffic, because internet router will learn all the vlans information from core switch, so return traffic would be internet routers-&amp;gt;core switch-&amp;gt;user subnets.&lt;/P&gt;&lt;P&gt;Or you may simply use PBR on internet routers to force return traffic go through core switches.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2019 11:34:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Asymmetric-routing-with-checkpoint-inline/m-p/49983#M9825</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-04-06T11:34:40Z</dc:date>
    </item>
    <item>
      <title>Re: Asymmetric routing with checkpoint inline.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Asymmetric-routing-with-checkpoint-inline/m-p/49984#M9826</link>
      <description>There is no routing concern here. firewall is not seeing full connection and will drop out of state packets. i also disabled drop out of state packets  from global properties to allow out of state packets but still its not working. we are able to ping but not access any website. in this design customer wants to use web filtering and QOS</description>
      <pubDate>Sat, 06 Apr 2019 11:48:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Asymmetric-routing-with-checkpoint-inline/m-p/49984#M9826</guid>
      <dc:creator>Sameer_Basha</dc:creator>
      <dc:date>2019-04-06T11:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Asymmetric routing with checkpoint inline.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Asymmetric-routing-with-checkpoint-inline/m-p/49985#M9827</link>
      <description>&lt;P&gt;Oh, I forgot to tell you such network design will cause many software blades invalid, because some deeper inspections or L7 functions needs to check return traffic as well.&lt;/P&gt;&lt;P&gt;And you can use zdebug or fw minitor to debug packet drop issues, I think you can check inspection settings, some tcp check will drop traffic.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Apr 2019 12:09:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Asymmetric-routing-with-checkpoint-inline/m-p/49985#M9827</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-04-06T12:09:05Z</dc:date>
    </item>
  </channel>
</rss>

