<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with routing based on ABR/PBR in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-routing-based-on-ABR-PBR/m-p/275448#M104913</link>
    <description>&lt;P&gt;&lt;SPAN class=""&gt;let have a brief of what is installed on the customer side : this is a swap porject from sophos to checkpoint, and each time i plan a migration, it is gone unsuccessful et we roll back.&lt;BR /&gt;&lt;BR /&gt;- Smart1 base 700S&lt;BR /&gt;&lt;BR /&gt;- 2 quantum 9100 in clusterXL HA configuration Mode : LAN port 172.16.4.0/22 and the Main IP address 172.16.7.254. DMZ 10.100.0.254/24 web services, 7 WANs interfaces 10.10.x.254/24 x from 11 to 17, each WAN is behind broadband isp router with static IP public let say 1.1.x.254,&lt;BR /&gt;&lt;BR /&gt;the customer has SDWAN routing on sophos but he only use it to match group with source IP addresses to loadbalancing its traffics to its 7 WANs.&lt;BR /&gt;&lt;BR /&gt;this source IP addresses groups have this logic :&lt;BR /&gt;- Group manager IP addresses take WAN1 to Internet and WAN2 as backup&lt;BR /&gt;- Group IT Stuff IP addresses take WAN7 to Internet and WAN1 as backup&lt;BR /&gt;and so on.&lt;BR /&gt;&lt;BR /&gt;unfortunately there is no sdwan features acquired but we have implement a solution based on PBR/ABR sk167135 so we route traffic based on PBR that match fw rules.&lt;BR /&gt;&lt;BR /&gt;the issue that we are facing instability behavior, sometimes its works and sometime no!!!&lt;BR /&gt;&lt;BR /&gt;[Expert@GAMemberGw1:0]# dbget -arv fwrules&lt;BR /&gt;fwrules:instance&lt;BR /&gt;fwrules:instance:default&lt;BR /&gt;fwrules:instance:default:rulenum&lt;BR /&gt;fwrules:instance:default:rulenum:39 t&lt;BR /&gt;fwrules:instance:default:rulenum:39:name PBR_Directeurs&lt;BR /&gt;fwrules:instance:default:rulenum:39:uuid 8467ccd2-9607-4789-8376-ddfa4e7f61e8&lt;BR /&gt;fwrules:instance:default:rulenum:40 t&lt;BR /&gt;fwrules:instance:default:rulenum:40:name PBR_DSI&lt;BR /&gt;fwrules:instance:default:rulenum:40:uuid 47bf3233-21b5-48cc-910c-8cc886ff7023&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;-------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;-------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Expert@GAMemberGw1:0]# ps aux | grep rtgpbrd&lt;BR /&gt;admin 1927 0.0 0.0 9148 1104 pts/1 S+ 18:34 0:00 grep --color=auto rtgpbrd&lt;BR /&gt;admin 23132 0.0 0.0 8392 4048 ? Ss 18:12 0:00 /bin/rtgpbrd&lt;BR /&gt;[Expert@GAMemberGw1:0]# cat /tmp/fwpbr*&lt;BR /&gt;cat: /tmp/fwpbr*: No such file or directory&lt;BR /&gt;[Expert@GAMemberGw1:0]#&lt;BR /&gt;Expert@GAMemberGw1:0]# ip rule&lt;BR /&gt;0: from all lookup local&lt;BR /&gt;101: from all fwmark 0x27000000/0xff000000 iif Mgmt lookup 1&lt;BR /&gt;102: from all fwmark 0x28000000/0xff000000 iif Mgmt lookup 2&lt;BR /&gt;103: from all fwmark 0x29000000/0xff000000 iif Mgmt lookup 3&lt;BR /&gt;104: from all fwmark 0x2a000000/0xff000000 iif Mgmt lookup 4&lt;BR /&gt;105: from all fwmark 0x2b000000/0xff000000 iif Mgmt lookup 5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Expert@GAMemberGw1:0]# ip route&lt;BR /&gt;1.1.1.1 proto 7&lt;BR /&gt;nexthop via 10.10.1.1 dev ethx1 weight 1&lt;BR /&gt;nexthop via 10.10.2.1 dev ethx2 weight 1&lt;BR /&gt;nexthop via 10.10.3.1 dev ethx3 weight 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;8.8.8.8 proto 7&lt;BR /&gt;nexthop via 10.10.1.1 dev ethx1 weight 1&lt;BR /&gt;nexthop via 10.10.2.1 dev ethx2 weight 1&lt;BR /&gt;nexthop via 10.10.3.1 dev ethx3 weight 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;--------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;C:\Users\meden&amp;gt;tracert &lt;A href="https://www.iam.ma" target="_blank" rel="noopener"&gt;www.iam.ma&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Détermination de l’itinéraire vers &lt;A href="https://www.iam.ma.cdn.cloudflare.net" target="_blank" rel="noopener"&gt;www.iam.ma.cdn.cloudflare.net&lt;/A&gt; [104.18.3.230]&lt;BR /&gt;avec un maximum de 30 sauts&amp;nbsp;:&lt;BR /&gt;&lt;BR /&gt;1 GAMemberGw1 [172.20.3.251] rapports&amp;nbsp;: Impossible de joindre le réseau de destination.&lt;BR /&gt;&lt;BR /&gt;Itinéraire déterminé.&lt;BR /&gt;&lt;BR /&gt;C:\Users\meden&amp;gt;tracert &lt;A href="https://www.iam.ma" target="_blank" rel="noopener"&gt;www.iam.ma&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Détermination de l’itinéraire vers &lt;A href="https://www.iam.ma.cdn.cloudflare.net" target="_blank" rel="noopener"&gt;www.iam.ma.cdn.cloudflare.net&lt;/A&gt; [104.18.3.230]&lt;BR /&gt;avec un maximum de 30 sauts&amp;nbsp;:&lt;BR /&gt;&lt;BR /&gt;1 GAMemberGw1 [172.20.3.251] rapports&amp;nbsp;: Impossible de joindre le réseau de destination.&lt;BR /&gt;&lt;BR /&gt;Itinéraire déterminé.&lt;BR /&gt;&lt;BR /&gt;C:\Users\meden&amp;gt;tracert &lt;A href="https://www.iam.ma" target="_blank" rel="noopener"&gt;www.iam.ma&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Détermination de l’itinéraire vers &lt;A href="https://www.iam.ma.cdn.cloudflare.net" target="_blank" rel="noopener"&gt;www.iam.ma.cdn.cloudflare.net&lt;/A&gt; [104.18.2.230]&lt;BR /&gt;avec un maximum de 30 sauts&amp;nbsp;:&lt;BR /&gt;&lt;BR /&gt;1 5 ms 4 ms 4 ms GAMemberGw1 [172.20.3.251] ---------- SGW IP LAN&lt;BR /&gt;2 5 ms 6 ms 7 ms 10.10.3.1&lt;BR /&gt;3 8 ms 14 ms 8 ms 41.141.160.1&lt;BR /&gt;^C&lt;BR /&gt;C:\Users\meden&amp;gt;tracert &lt;A href="https://www.iam.ma" target="_blank" rel="noopener"&gt;www.iam.ma&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Détermination de l’itinéraire vers &lt;A href="https://www.iam.ma.cdn.cloudflare.net" target="_blank" rel="noopener"&gt;www.iam.ma.cdn.cloudflare.net&lt;/A&gt; [104.18.2.230]&lt;BR /&gt;avec un maximum de 30 sauts&amp;nbsp;:&lt;BR /&gt;&lt;BR /&gt;1 GAMemberGw1 [172.20.3.251] rapports&amp;nbsp;: Impossible de joindre le réseau de destination.&lt;BR /&gt;&lt;BR /&gt;Itinéraire déterminé.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Any one can help please?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Apr 2026 21:24:14 GMT</pubDate>
    <dc:creator>mohammed1987</dc:creator>
    <dc:date>2026-04-14T21:24:14Z</dc:date>
    <item>
      <title>Issue with routing based on ABR/PBR</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-routing-based-on-ABR-PBR/m-p/275448#M104913</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;let have a brief of what is installed on the customer side : this is a swap porject from sophos to checkpoint, and each time i plan a migration, it is gone unsuccessful et we roll back.&lt;BR /&gt;&lt;BR /&gt;- Smart1 base 700S&lt;BR /&gt;&lt;BR /&gt;- 2 quantum 9100 in clusterXL HA configuration Mode : LAN port 172.16.4.0/22 and the Main IP address 172.16.7.254. DMZ 10.100.0.254/24 web services, 7 WANs interfaces 10.10.x.254/24 x from 11 to 17, each WAN is behind broadband isp router with static IP public let say 1.1.x.254,&lt;BR /&gt;&lt;BR /&gt;the customer has SDWAN routing on sophos but he only use it to match group with source IP addresses to loadbalancing its traffics to its 7 WANs.&lt;BR /&gt;&lt;BR /&gt;this source IP addresses groups have this logic :&lt;BR /&gt;- Group manager IP addresses take WAN1 to Internet and WAN2 as backup&lt;BR /&gt;- Group IT Stuff IP addresses take WAN7 to Internet and WAN1 as backup&lt;BR /&gt;and so on.&lt;BR /&gt;&lt;BR /&gt;unfortunately there is no sdwan features acquired but we have implement a solution based on PBR/ABR sk167135 so we route traffic based on PBR that match fw rules.&lt;BR /&gt;&lt;BR /&gt;the issue that we are facing instability behavior, sometimes its works and sometime no!!!&lt;BR /&gt;&lt;BR /&gt;[Expert@GAMemberGw1:0]# dbget -arv fwrules&lt;BR /&gt;fwrules:instance&lt;BR /&gt;fwrules:instance:default&lt;BR /&gt;fwrules:instance:default:rulenum&lt;BR /&gt;fwrules:instance:default:rulenum:39 t&lt;BR /&gt;fwrules:instance:default:rulenum:39:name PBR_Directeurs&lt;BR /&gt;fwrules:instance:default:rulenum:39:uuid 8467ccd2-9607-4789-8376-ddfa4e7f61e8&lt;BR /&gt;fwrules:instance:default:rulenum:40 t&lt;BR /&gt;fwrules:instance:default:rulenum:40:name PBR_DSI&lt;BR /&gt;fwrules:instance:default:rulenum:40:uuid 47bf3233-21b5-48cc-910c-8cc886ff7023&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;-------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;-------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Expert@GAMemberGw1:0]# ps aux | grep rtgpbrd&lt;BR /&gt;admin 1927 0.0 0.0 9148 1104 pts/1 S+ 18:34 0:00 grep --color=auto rtgpbrd&lt;BR /&gt;admin 23132 0.0 0.0 8392 4048 ? Ss 18:12 0:00 /bin/rtgpbrd&lt;BR /&gt;[Expert@GAMemberGw1:0]# cat /tmp/fwpbr*&lt;BR /&gt;cat: /tmp/fwpbr*: No such file or directory&lt;BR /&gt;[Expert@GAMemberGw1:0]#&lt;BR /&gt;Expert@GAMemberGw1:0]# ip rule&lt;BR /&gt;0: from all lookup local&lt;BR /&gt;101: from all fwmark 0x27000000/0xff000000 iif Mgmt lookup 1&lt;BR /&gt;102: from all fwmark 0x28000000/0xff000000 iif Mgmt lookup 2&lt;BR /&gt;103: from all fwmark 0x29000000/0xff000000 iif Mgmt lookup 3&lt;BR /&gt;104: from all fwmark 0x2a000000/0xff000000 iif Mgmt lookup 4&lt;BR /&gt;105: from all fwmark 0x2b000000/0xff000000 iif Mgmt lookup 5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Expert@GAMemberGw1:0]# ip route&lt;BR /&gt;1.1.1.1 proto 7&lt;BR /&gt;nexthop via 10.10.1.1 dev ethx1 weight 1&lt;BR /&gt;nexthop via 10.10.2.1 dev ethx2 weight 1&lt;BR /&gt;nexthop via 10.10.3.1 dev ethx3 weight 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;8.8.8.8 proto 7&lt;BR /&gt;nexthop via 10.10.1.1 dev ethx1 weight 1&lt;BR /&gt;nexthop via 10.10.2.1 dev ethx2 weight 1&lt;BR /&gt;nexthop via 10.10.3.1 dev ethx3 weight 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;--------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;C:\Users\meden&amp;gt;tracert &lt;A href="https://www.iam.ma" target="_blank" rel="noopener"&gt;www.iam.ma&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Détermination de l’itinéraire vers &lt;A href="https://www.iam.ma.cdn.cloudflare.net" target="_blank" rel="noopener"&gt;www.iam.ma.cdn.cloudflare.net&lt;/A&gt; [104.18.3.230]&lt;BR /&gt;avec un maximum de 30 sauts&amp;nbsp;:&lt;BR /&gt;&lt;BR /&gt;1 GAMemberGw1 [172.20.3.251] rapports&amp;nbsp;: Impossible de joindre le réseau de destination.&lt;BR /&gt;&lt;BR /&gt;Itinéraire déterminé.&lt;BR /&gt;&lt;BR /&gt;C:\Users\meden&amp;gt;tracert &lt;A href="https://www.iam.ma" target="_blank" rel="noopener"&gt;www.iam.ma&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Détermination de l’itinéraire vers &lt;A href="https://www.iam.ma.cdn.cloudflare.net" target="_blank" rel="noopener"&gt;www.iam.ma.cdn.cloudflare.net&lt;/A&gt; [104.18.3.230]&lt;BR /&gt;avec un maximum de 30 sauts&amp;nbsp;:&lt;BR /&gt;&lt;BR /&gt;1 GAMemberGw1 [172.20.3.251] rapports&amp;nbsp;: Impossible de joindre le réseau de destination.&lt;BR /&gt;&lt;BR /&gt;Itinéraire déterminé.&lt;BR /&gt;&lt;BR /&gt;C:\Users\meden&amp;gt;tracert &lt;A href="https://www.iam.ma" target="_blank" rel="noopener"&gt;www.iam.ma&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Détermination de l’itinéraire vers &lt;A href="https://www.iam.ma.cdn.cloudflare.net" target="_blank" rel="noopener"&gt;www.iam.ma.cdn.cloudflare.net&lt;/A&gt; [104.18.2.230]&lt;BR /&gt;avec un maximum de 30 sauts&amp;nbsp;:&lt;BR /&gt;&lt;BR /&gt;1 5 ms 4 ms 4 ms GAMemberGw1 [172.20.3.251] ---------- SGW IP LAN&lt;BR /&gt;2 5 ms 6 ms 7 ms 10.10.3.1&lt;BR /&gt;3 8 ms 14 ms 8 ms 41.141.160.1&lt;BR /&gt;^C&lt;BR /&gt;C:\Users\meden&amp;gt;tracert &lt;A href="https://www.iam.ma" target="_blank" rel="noopener"&gt;www.iam.ma&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Détermination de l’itinéraire vers &lt;A href="https://www.iam.ma.cdn.cloudflare.net" target="_blank" rel="noopener"&gt;www.iam.ma.cdn.cloudflare.net&lt;/A&gt; [104.18.2.230]&lt;BR /&gt;avec un maximum de 30 sauts&amp;nbsp;:&lt;BR /&gt;&lt;BR /&gt;1 GAMemberGw1 [172.20.3.251] rapports&amp;nbsp;: Impossible de joindre le réseau de destination.&lt;BR /&gt;&lt;BR /&gt;Itinéraire déterminé.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Any one can help please?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Apr 2026 21:24:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Issue-with-routing-based-on-ABR-PBR/m-p/275448#M104913</guid>
      <dc:creator>mohammed1987</dc:creator>
      <dc:date>2026-04-14T21:24:14Z</dc:date>
    </item>
  </channel>
</rss>

