Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Hllrdm
Contributor

Rank and Cost in Check Point

I want to figure out the rank-to-cost ratio in Check Point routing.
We can adjust Rank between static routes, dynamic protocols, but we don't see a cost adjustment for routes. We know that rank and cost affect the order in which packets are sent through the routing table.We tried to set the same rank between the static route and the rank that comes in via ospf. In this case traffic went via ospf route, cost of ospf was lower than that of static route.
When we output show route, we see cost, but we don't see rank. How do these concepts relate to Check Point?


0 Kudos
9 Replies
_Val_
Admin
Admin

Please provide a specific example. 

0 Kudos
Hllrdm
Contributor

We are preparing an example. Maybe you can tell us how cost and rank are related in Check Point?

0 Kudos
_Val_
Admin
Admin

Nothing special with Check Point. Lower cost should be the preferable route. Not sure what you mean by "rank" though.

Please also refer to the advanced routing guide for your version, for example: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityGateway_Guide/Conten...

 

0 Kudos
Chris_Atkinson
Employee Employee
Employee

The "Protocol Rank" concept is described here:

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Gaia_Advanced_Routing_AdminG... 

CCSM R77/R80/ELITE
0 Kudos
MiniNinja
Collaborator

And what about the priority in relation to Ipsec VPN domain, what is the priority of networks (routes) in the VPN domain?

 

0 Kudos
PhoneBoy
Admin
Admin

Domain-Based VPN traffic (as opposed to Route/Based VPN with VTIs) always takes priority over other routes due to VPN’s position in the kernel.

0 Kudos
MiniNinja
Collaborator

which is more priority than a static route or a VPN domain?

0 Kudos
PhoneBoy
Admin
Admin

Pretty sure a VPN Domain has higher priority.

the_rock
Legend
Legend

I always thought domain based tunnel has priority over route based one, but then static route would have precedence over VPN domain.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events