Firewall-1

[FW-1] Site-to-site behind a NAT device

Subject: [FW-1] Site-to-site behind a NAT device
From: Nick Brandson <nickbrandson AT YAHOO DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Tue, 22 Mar 2005 22:34:07 -0800
Dear guru,

Does anyone try build site-to-site VPN with one
gateway behind a NAT device (like a router or a load
balancer)?

Both gateways are using NGAI R55 on SecurePlatform.
Want to use a load balancer for two ISPs link.  The
primary link can be transparently go thru the LB
device, the secondary link needs to be NATted to the
Firewall. From the Firewall point of view, only one
connection to the device.  The device will make the
decisions.  We do NOT turn on the ISP redundancy in
CP.

what we need to set up in the peer gateway in order to
identify the changes when ISP link failover.

Do we need to set up two Firewall Objects in the peer
gateway?

Any ideas/input will be much appreciated.

Thanks a million,
Nick



__________________________________
Do you Yahoo!?
Make Yahoo! your home page
http://www.yahoo.com/r/hs

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>