- Products
- Learn
- Local User Groups
- Partners
- More
CheckMates Fifth Birthday
Celebrate with Us!
days
hours
minutes
seconds
Join the CHECKMATES Everywhere Competition
Submit your picture to win!
Check Point Proactive support
Free trial available for 90 Days!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
The 2022 MITRE Engenuity ATT&CK®
Evaluations Results Are In!
Now Available: SmartAwareness Security Training
Training Built to Educate and Engage
MITRE ATT&CK
Inside Check Point products!
CheckFlix!
All Videos In One Space
Hello
customer is a TELCO/ISP and has procured checkpoint 15600 cluster. firewall will be used to filter customers traffic and apply quality of service on them. customer wants the firewall to support asymmetric traffic. only the outgoing connections will go through the firewall and return traffic will be directly routed to the core switch from the router. i have attached the design.
default gateway of core switch is firewall
on the router the return traffic is routed back to the core switch.
is there any way we can make it work. please confirm
Maybe dynamic routing protocols can achieve your requirement....
CP15600 cluster points the default static route to internet router, then redistribute to ospf instance, then core switch would learn this default information, the client traffic will then go through core switch->CP15600 cluster->internet router, as for the return traffic, because internet router will learn all the vlans information from core switch, so return traffic would be internet routers->core switch->user subnets.
Or you may simply use PBR on internet routers to force return traffic go through core switches.
Oh, I forgot to tell you such network design will cause many software blades invalid, because some deeper inspections or L7 functions needs to check return traffic as well.
And you can use zdebug or fw minitor to debug packet drop issues, I think you can check inspection settings, some tcp check will drop traffic.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY