- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Rank and Cost in Check Point
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Rank and Cost in Check Point
I want to figure out the rank-to-cost ratio in Check Point routing.
We can adjust Rank between static routes, dynamic protocols, but we don't see a cost adjustment for routes. We know that rank and cost affect the order in which packets are sent through the routing table.We tried to set the same rank between the static route and the rank that comes in via ospf. In this case traffic went via ospf route, cost of ospf was lower than that of static route.
When we output show route, we see cost, but we don't see rank. How do these concepts relate to Check Point?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please provide a specific example.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We are preparing an example. Maybe you can tell us how cost and rank are related in Check Point?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nothing special with Check Point. Lower cost should be the preferable route. Not sure what you mean by "rank" though.
Please also refer to the advanced routing guide for your version, for example: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityGateway_Guide/Conten...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The "Protocol Rank" concept is described here:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
And what about the priority in relation to Ipsec VPN domain, what is the priority of networks (routes) in the VPN domain?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Domain-Based VPN traffic (as opposed to Route/Based VPN with VTIs) always takes priority over other routes due to VPN’s position in the kernel.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
which is more priority than a static route or a VPN domain?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Pretty sure a VPN Domain has higher priority.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I always thought domain based tunnel has priority over route based one, but then static route would have precedence over VPN domain.
Andy
