<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic static route redundancy with different priority nexthop gateways using alternate monitored address in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-route-redundancy-with-different-priority-nexthop-gateways/m-p/98058#M10491</link>
    <description>&lt;P&gt;Hi checkmates,&lt;/P&gt;&lt;P&gt;I want to configure route redundancy for a specific static route where the nexthop should be an upstream vpn gateway as priority 1 path and a connected router for priority 2 path.&lt;BR /&gt;The priority 2 route should become active when the vpn goes down.&lt;/P&gt;&lt;P&gt;Form my understanding the default nexthop ping monitoring would make no sense since the priority 1 nexthop (upstream vpn gateway) would still be active in case of vpn breakdown.&lt;/P&gt;&lt;P&gt;My idea is to create a dedicated ip on the upstream vpn gateway which then DNAT to a vpn internal remote ip.&lt;BR /&gt;This ip should be monitored from the checkpoint and if not reachable then issue the routing failover (priority 2) route.&lt;/P&gt;&lt;P&gt;# monitored nexthop, will be DNATed on the upstream vpn gateway to internal vpn endpoint&lt;BR /&gt;set static-route 1.25.93.1/32 nexthop gateway address 1.1.1.100 on&lt;/P&gt;&lt;P&gt;# failover to priority 2 nexthop, failback to priority 1 nexthop once monitored ip becomes up again&lt;BR /&gt;set static-route 1.25.80.0/20 nexthop gateway address 1.1.1.4 priority 1 on&lt;BR /&gt;set static-route 1.25.80.0/20 nexthop gateway address 1.2.1.4 priority 2 on&lt;/P&gt;&lt;P&gt;I have R80.30 and read about BFD using ICMP ping which would be a possibility but there's not much info on this.&lt;/P&gt;&lt;P&gt;Also do I have to add one route with two gateways and different priorities or two separate identical routes with each gateway using different priorities?&lt;/P&gt;&lt;P&gt;Can someone help me with this?&lt;/P&gt;</description>
    <pubDate>Fri, 02 Oct 2020 09:10:05 GMT</pubDate>
    <dc:creator>soundwave</dc:creator>
    <dc:date>2020-10-02T09:10:05Z</dc:date>
    <item>
      <title>static route redundancy with different priority nexthop gateways using alternate monitored address</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-route-redundancy-with-different-priority-nexthop-gateways/m-p/98058#M10491</link>
      <description>&lt;P&gt;Hi checkmates,&lt;/P&gt;&lt;P&gt;I want to configure route redundancy for a specific static route where the nexthop should be an upstream vpn gateway as priority 1 path and a connected router for priority 2 path.&lt;BR /&gt;The priority 2 route should become active when the vpn goes down.&lt;/P&gt;&lt;P&gt;Form my understanding the default nexthop ping monitoring would make no sense since the priority 1 nexthop (upstream vpn gateway) would still be active in case of vpn breakdown.&lt;/P&gt;&lt;P&gt;My idea is to create a dedicated ip on the upstream vpn gateway which then DNAT to a vpn internal remote ip.&lt;BR /&gt;This ip should be monitored from the checkpoint and if not reachable then issue the routing failover (priority 2) route.&lt;/P&gt;&lt;P&gt;# monitored nexthop, will be DNATed on the upstream vpn gateway to internal vpn endpoint&lt;BR /&gt;set static-route 1.25.93.1/32 nexthop gateway address 1.1.1.100 on&lt;/P&gt;&lt;P&gt;# failover to priority 2 nexthop, failback to priority 1 nexthop once monitored ip becomes up again&lt;BR /&gt;set static-route 1.25.80.0/20 nexthop gateway address 1.1.1.4 priority 1 on&lt;BR /&gt;set static-route 1.25.80.0/20 nexthop gateway address 1.2.1.4 priority 2 on&lt;/P&gt;&lt;P&gt;I have R80.30 and read about BFD using ICMP ping which would be a possibility but there's not much info on this.&lt;/P&gt;&lt;P&gt;Also do I have to add one route with two gateways and different priorities or two separate identical routes with each gateway using different priorities?&lt;/P&gt;&lt;P&gt;Can someone help me with this?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Oct 2020 09:10:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-route-redundancy-with-different-priority-nexthop-gateways/m-p/98058#M10491</guid>
      <dc:creator>soundwave</dc:creator>
      <dc:date>2020-10-02T09:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: static route redundancy with different priority nexthop gateways using alternate monitored addre</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-route-redundancy-with-different-priority-nexthop-gateways/m-p/98232#M10492</link>
      <description>&lt;P&gt;From CLI you will need to add a route twice with each gateway using different priorities. In WebUI, you can add two different gateways to a given route. Just to clarify, BFD does not use ICMP. You can use remote-ip monitoring with either ICMP or BFD. Please involve PS, SE or Diamond to help with configuration.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 16:08:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-route-redundancy-with-different-priority-nexthop-gateways/m-p/98232#M10492</guid>
      <dc:creator>Sundeep_Mudgal</dc:creator>
      <dc:date>2020-10-05T16:08:46Z</dc:date>
    </item>
  </channel>
</rss>

