Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Load Balancing Firewalls

I have a customer who wants to know if load balancing 2 Checkpoint firewalls can be acheived by using local directors.

Would this require a local director inside and outside of both firewalls?

How would a conversation that passes through a local director in one direction, be aware on the other side that it has to pass back via a certain firewall?

thanks, Mark.

7 REPLIES
New Member

Re: Load Balancing Firewalls

I wouldn't recommend it. It would be a similar build to a 'Fully Clad' F5 networks impletmentation of load balancers inside and outside, with session stickiness.

You would be much better off using the CSS switches, as they have a number of features to assist in this, as well as examples.

New Member

Re: Load Balancing Firewalls

use the CSS. I did it for an ISP across the US. Works fine.

New Member

Re: Load Balancing Firewalls

Thanks for both replies, I'll reccommend the CSS.

Does this mean its not possible to have a "sticky" connection using Local Directors either side of a firewall?

New Member

Re: Load Balancing Firewalls

Well, the LocalDirectors can have sticky sessions, but I have to agree with the other posts here. It is not designed for firewall loadbalancing, more for small scale Webservers and stuff like that. The CSS series is far better equipped to do this.

New Member

Re: Load Balancing Firewalls

You should use the CSS's for load balancing firewalls. I don't believe you can use the localdir's for that purpose anyway. The stateful inspection of the FW would prevent alot of the traffic. The CSS's have a way of directing the session through the same firewall it is already established through.

New Member

Re: Load Balancing Firewalls

not sure what the cisco solution is but the Alteon webswitch will handle this

New Member

Re: Load Balancing Firewalls

I suggest you use two css switch to load balance checkpoint firewall,better than local director.

270
Views
0
Helpful
7
Replies