LedZepRock
MIS
Hi
Odd one this... I have a client that wishes to setup a VPN connection between his PIX and our Checkpoint, now the VPN is no trouble but he is asking that the Phase 1 part of the VPN be kept "always connected", I am unsure to what his motives for this is!! It is a failover system that will be only rarely used, so its not the overhead of negotiation, I am really unsure, so I have 2 questions...
1, Can the checkpoint be configured to work like this??
2, Am I missing something about why keeping it always on is a good idea????
Any thoughts would be great.
Thanks
Simon
Odd one this... I have a client that wishes to setup a VPN connection between his PIX and our Checkpoint, now the VPN is no trouble but he is asking that the Phase 1 part of the VPN be kept "always connected", I am unsure to what his motives for this is!! It is a failover system that will be only rarely used, so its not the overhead of negotiation, I am really unsure, so I have 2 questions...
1, Can the checkpoint be configured to work like this??
2, Am I missing something about why keeping it always on is a good idea????
Any thoughts would be great.
Thanks
Simon