Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted
Employee
Employee

Asymmetric routing with checkpoint inline.

Hello 

design.png

 

customer is a TELCO/ISP and has procured checkpoint 15600 cluster. firewall will be used to filter customers traffic and apply quality of service on them. customer wants the firewall to support asymmetric traffic. only the outgoing connections will go through the firewall and return traffic will be directly routed to the core switch from the router. i have attached the design. 

default gateway of core switch is firewall

on the router the return traffic is routed back to the core switch. 

is there any way we can make it work. please confirm

 

0 Kudos
Reply
3 Replies
Highlighted
Advisor

Maybe dynamic routing protocols can achieve your requirement....

CP15600 cluster points the default static route to internet router, then redistribute to ospf instance, then core switch would learn this default information, the client traffic will then go through core switch->CP15600 cluster->internet router, as for the return traffic, because internet router will learn all the vlans information from core switch, so return traffic would be internet routers->core switch->user subnets.

Or you may simply use PBR on internet routers to force return traffic go through core switches.

 

 

 

0 Kudos
Reply
Highlighted
Employee
Employee

There is no routing concern here. firewall is not seeing full connection and will drop out of state packets. i also disabled drop out of state packets from global properties to allow out of state packets but still its not working. we are able to ping but not access any website. in this design customer wants to use web filtering and QOS
0 Kudos
Reply
Highlighted
Advisor

Oh, I forgot to tell you such network design will cause many software blades invalid, because some deeper inspections or L7 functions needs to check return traffic as well.

And you can use zdebug or fw minitor to debug packet drop issues, I think you can check inspection settings, some tcp check will drop traffic.

0 Kudos
Reply