- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hello
customer is a TELCO/ISP and has procured checkpoint 15600 cluster. firewall will be used to filter customers traffic and apply quality of service on them. customer wants the firewall to support asymmetric traffic. only the outgoing connections will go through the firewall and return traffic will be directly routed to the core switch from the router. i have attached the design.
default gateway of core switch is firewall
on the router the return traffic is routed back to the core switch.
is there any way we can make it work. please confirm
Maybe dynamic routing protocols can achieve your requirement....
CP15600 cluster points the default static route to internet router, then redistribute to ospf instance, then core switch would learn this default information, the client traffic will then go through core switch->CP15600 cluster->internet router, as for the return traffic, because internet router will learn all the vlans information from core switch, so return traffic would be internet routers->core switch->user subnets.
Or you may simply use PBR on internet routers to force return traffic go through core switches.
Oh, I forgot to tell you such network design will cause many software blades invalid, because some deeper inspections or L7 functions needs to check return traffic as well.
And you can use zdebug or fw minitor to debug packet drop issues, I think you can check inspection settings, some tcp check will drop traffic.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY