Advertisement

06.24.2008 at 01:22PM PDT, ID: 23512504
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

6.6

Help Setting up BGP with two ISP providers and 1 Checkpoint Firewall VPN-1 UTM running SPLAT

Asked by rdelrosario in ISPs & Web Hosting, Checkpoint Firewall, Network Management

Tags:

We have a Checkpoint NGX R65 VPN-1 UTM Firewall running SPLAT.   It has 3 interfaces.  1 public interface (to our T1 Router), 1 DMZ interface, 1 Internal Lan Interface.

We are wanting to have another ISP for Internet Redundancy and wanted to implement BGP.   However, I've read conflicting information regarding the physical & Logical implementation.   Here is my understanding of how we can implement BGP with our current configuration.   WE DO NOT have the option of running another firewall.

First some questions to get out of the way:

1.  We don't need to do anything with the Firewall correct?  BGP is done at the router level and then it just hands the packets to the firewall?  So need to change anything on the Checkpoint Firewall?

2.  BGP does not load balance, but I can pre-determine what provider to use as the primary correct?

3.  Packets never flow from both routers at the same time in a BGP setup right?  Its either going to be one ISP's router talking at a time, not both?

Regarding the physical implementation:
Assuming I pick up another provider say XO communication for our 2nd provider and they supply us with a BGP capable router....   Can I then just unplug the cat5 connection from our primary router (verizon) from the Public interface on the firewall... introduce a shared hub... then plug in both Verizon and XO routers into the shared hub, then plug the public interface of the firewall to the shared hub so that all 3 devices can see each other...   then let BGP do its thing.

Regarding the logical routing:
I assume that I can have 1 provider be the primary ISP and be used all the time unless it is unavailable.  In this situation, I'd like the XO provider to take inbound traffic to the IP's that were originally assigned by our verizon provider.  We'd also like to have all outbound traffic always use XO as it is likely going to be a fatter pipe.

I'm to understand that in a nut shell:
1.  apply for an ASN.
2.  setup BGP with each router.
3.  hookup each router to the firewall

Please advise to the above and any things worth noting that maybe an issue from my limited description.  Start Free Trial
 
 
[+][-]06.24.2008 at 02:00PM PDT, ID: 21860354

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.24.2008 at 02:45PM PDT, ID: 21860689

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]06.24.2008 at 02:52PM PDT, ID: 21860740

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.26.2008 at 07:26AM PDT, ID: 21875153

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]06.26.2008 at 10:56AM PDT, ID: 21877301

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.26.2008 at 12:43PM PDT, ID: 21878293

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]06.26.2008 at 02:43PM PDT, ID: 21879312

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.26.2008 at 04:43PM PDT, ID: 21879956

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]06.26.2008 at 05:26PM PDT, ID: 21880165

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]06.26.2008 at 06:05PM PDT, ID: 21880293

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]06.30.2008 at 03:31PM PDT, ID: 21903566

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: ISPs & Web Hosting, Checkpoint Firewall, Network Management
Tags: BGP ISP Redundancy Routing Firewalls
Sign Up Now!
Solution Provided By: fileinster
Participating Experts: 1
Solution Grade: A
 
 
[+][-]06.30.2008 at 03:33PM PDT, ID: 21903579

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628