Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ham2065
Explorer

External Topology and Addressing

Hi 

 

We have an ARIN assigned  /24 public range. The physical topology of external internet link is the typical ISP <> External Router <> Layer2 Switches <> Checkpoint ClusterXL. 

 

Is it best to use /24 for addressing the external Checkpoint ClusterXL interfaces/VIP or use a smaller /28 or /29 for addressing the external Checkpoint ClusterXL interfaces and then route the /24 range on the External Router to the Checkpoint ClusterXL VIP interface?

I know both will work but wanted to get some feedback on best practices and security considerations. Note - we also have DDoS protection/scubbing on the /24 range. As a result is it safer to use the first option?

 

 

0 Kudos
3 Replies
This widget could not be displayed.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events