- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Help with Remote Access concentrator in Azure
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Help with Remote Access concentrator in Azure
Hello,
I'd like to share a scenario and see if anyone has experienced something similar and what your experience was.
I plan to deploy a Check Point cluster in Azure to act as a VPN concentrator for remote users. In the worst-case scenario, there will be around 2,000 concurrent users.
My concern is about the connection table. Due to a particularity of the environment, I can't configure routing within Azure to send packets originating from the Office Mode network back to the Check Point, so I'll need to use Hide NAT.
In Azure, I'm also unable to allocate additional IP addresses to the Check Point's back-end interface in order to create a NAT pool with multiple addresses. As a result, all 2,000 users will be sharing a single NAT IP. Could this cause the connection table to become overloaded?
Thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There's a limit to the number of HIDE NAT connections to a single destination IP (50,000).
This is probably the limit you will hit before you exhaust the overall connection table.
