16.04.2015 Views

NGX R65 Release Notes - Check Point

NGX R65 Release Notes - Check Point

NGX R65 Release Notes - Check Point

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ClusterXL<br />

46. Peer or secure remote gateways may show error messages when working against an overloaded<br />

gateway cluster in Load Sharing mode. This is due to IPsec packets with an old replay counter.<br />

These error messages can be safely ignored.<br />

47. Using Sticky Decision Function with VPN features will guarantee connection stickiness for<br />

connections that pass through the cluster only, and not to connections originating from a<br />

cluster member or to it.<br />

48. When a <strong>Check</strong> <strong>Point</strong> VPN-1 <strong>NGX</strong> peer is connected directly to a <strong>Check</strong> <strong>Point</strong> cluster (i.e., the<br />

peer and the cluster are located on the same VLAN and there is no Layer 3 (IP) routing device<br />

between them), the following features are not supported:<br />

• ISP Redundancy<br />

• VPN link selection - Reply from same interface<br />

This issue can be resolved either by placing a router between the VPN peer and the cluster, or<br />

by disabling these features. (Neither feature is enabled by default.)<br />

• To disable ISP redundancy, in SmartDashboard edit the gateway object > Topology > ISP<br />

Redundancy, and remove the check mark from Support ISP Redundancy.<br />

• To disable VPN link selection - Reply from the same interface, in SmartDashboard edit the<br />

gateway object > VPN > Link Selection > Outgoing Route Selection, and do the following:<br />

A. Under When initiating a tunnel, enable Operating system routing table,<br />

B. and under When responding to remotely initiated tunnel, select Setup, and enable Use<br />

outgoing traffic configuration.<br />

49. When configuring a VTI cluster interface, it should be assigned a name identical to the name<br />

of the member interface.<br />

VPN-1/FireWall-1 <strong>NGX</strong> <strong>R65</strong> Known Limitations Supplement. Last Update — February 4, 2008 5:37 pm 10

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!