Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Khanh134752
Explorer

enable asynmetric routing firewall checkpoint

Dear experts
Currently running Cisco Firepower 2110 Model, using the configuration for 3 Public lines is still running normally but replacing CheckPoint firewall is an error.
Traffic flow usually sets the host file at all 3 public IPs is still in normal service Traffic when changing the CheckPoint firewall to the client is only called in the direction that the CheckPoint Firewall is setting the data at the lowest level (As shown below) I don't know if the CheckPoint Firewall has a mechanism to check the entire stateful routing table before it can pass, right? At Cisco firewalls, the processor follows the previous Statefull table, the system operates normally. If that's true, is there a way to make the CheckPoint Firewall work like the Cisco Firewall?

0 Kudos
2 Replies
emmap
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

If I'm following, I don't think there's a way to do it in a single routing instance, but if you used VSX to split the system into 3 instances (VRFs, basically) then it may be workable that way.

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

You might be able to use PBR to help, otherwise the Check Point would probably need to be doing the NAT based on Security Zone?

Otherwise you have the solution as indicated by Emma.

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events