Tuesday 30 October 2012

VPN Probing in Checkpoint

VPN Probing in Checkpoint

Use probing method
If a gateway has multiple IP addresses available for VPN traffic, then the correct address for
VPN is discovered through one of the following probing methods:

Using ongoing probing - When a session is initiated, all possible destination IP addresses
continuously receive RDP packets until one of them responds. Connections go through the
first IP to respond (or to a primary IP if a primary IP is configured and active), and stay with
this IP until the IP stops responding. The RDP probing is activated when a connection is
opened and continues as a background process.

Using one time probing - When a session is initiated, all possible destination IP addresses
receive a lone RDP session to test the route. The first IP to respond is chosen, and stays
chosen until the next time a policy is installed.
For both the probing options (one-time and ongoing) a Primary Interface can be assigned. If
not all of a gateway's interfaces are used for VPN, a smaller set of interfaces can be selected.

1 comment:


  1. This is a great post. I like this topic.This site has lots of advantage.I found many interesting things from this site. It helps me in many ways.Thanks for posting this again.
    testimonials

    ReplyDelete