<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISP Redundancy - 2 default route pointing to different ISP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18759#M1445</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are on Gaia, use&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;set static-route default nexthop gateway address&amp;nbsp; on|off &lt;/PRE&gt;&lt;P&gt;to add or delete a static route.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Always conclude with&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;save config&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Aug 2018 15:40:20 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2018-08-14T15:40:20Z</dc:date>
    <item>
      <title>ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18749#M1435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;Can we add 2 default route on checkpoint firewall pointing to two different ISP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;for example:&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #fafafa; font-size: 13px;" /&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;0.0.0.0/0 ---&amp;gt; ISP A&lt;/SPAN&gt;&lt;BR style="color: #333333; background-color: #fafafa; font-size: 13px;" /&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;0.0.0.0/0 ---&amp;gt; ISP B&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;I am trying to do load balancing between 2 ISP through ISP redundancy ( weight 50% for both ISP)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;But due to default route pointing to ISP A. All traffic leaves through ISP A and ISP B is never utilized. As i add another default route on firewall for ISP B with same cost, Traffic start leaving ISP B as well.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;But after some time firewall removes ISP B route automatically. I want it to be in routing table always. Is this correct design?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;I am doing hide NAT as well with 2 ISP external interface as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #fafafa; font-size: 13px;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 09:37:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18749#M1435</guid>
      <dc:creator>Ankur_Datta1</dc:creator>
      <dc:date>2018-08-14T09:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18750#M1436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check these guides:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R77/CP_R77_SecurityGatewayTech_WebAdmin/89364.htm" title="https://sc1.checkpoint.com/documents/R77/CP_R77_SecurityGatewayTech_WebAdmin/89364.htm"&gt;ISP Redundancy&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/12314/FILE/How_To_Configure_ISP_Redundancy.pdf" title="https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/12314/FILE/How_To_Configure_ISP_Redundancy.pdf"&gt;How To Configure ISP Redundancy&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;To enable ISP Redundancy:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Open the network object properties of the Security Gateway or cluster.&lt;/LI&gt;&lt;LI&gt;Click Other &amp;gt; ISP Redundancy.&lt;/LI&gt;&lt;LI&gt;Select Support ISP Redundancy.&lt;/LI&gt;&lt;LI&gt;Select Load Sharing or Primary/Backup.&lt;/LI&gt;&lt;LI&gt;Configure the links.&lt;/LI&gt;&lt;LI&gt;Configure the Security Gateway to be the DNS server.&lt;/LI&gt;&lt;LI&gt;Configure the policy for ISP Redundancy.&lt;/LI&gt;&lt;/OL&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 10:29:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18750#M1436</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-08-14T10:29:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18751#M1437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&amp;nbsp;Aleksei,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply. I already configured ISP redundancy on firewall with option checked as load sharing. but in routing table i can only see 1 default route pointing to ISP A as configured through gaia web-portal. I added another default route through CLI:&lt;/P&gt;&lt;P&gt;set static-route default nexthop gateway address&amp;nbsp;ISP-B on&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now routing table shows 2 default route pointing to ISP - A and ISP - B&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;S 0.0.0.0/0 via ISP - B, eth2, cost 0, age 5786&lt;BR /&gt; via ISP - A, eth1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i save the config.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;traffic is traversing through both path but after some time firewall loose the default route added through CLI and again traffic start traversing through ISP -A path.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly suggest.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 10:45:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18751#M1437</guid>
      <dc:creator>Ankur_Datta1</dc:creator>
      <dc:date>2018-08-14T10:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18752#M1438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that's a normal behaviour.&lt;/P&gt;&lt;P&gt;There shoud be one manually configured default route pointing to the primary ISP. Other settings are taken from ISP redundancy configuration in policy.&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;When the Security Gateway starts, or an ISP link state changes, the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;EM class="" style="color: #000000; background-color: #ffffff; font-size: 12px; padding: 0pt;"&gt;$FWDIR/bin/cpisp_update&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;script runs. It changes the default route of the Security Gateway.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are also some advanced configurations possible and there it might be required to change text files. But in your case it should be a standard config in SmartDashborad only.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 14:29:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18752#M1438</guid>
      <dc:creator>AlekseiShelepov</dc:creator>
      <dc:date>2018-08-14T14:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18753#M1439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for update. How can we acheive load sharing then if there is only default route pointing towards ISP -A and we want traffic should traverse through both links?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 14:47:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18753#M1439</guid>
      <dc:creator>Ankur_Datta1</dc:creator>
      <dc:date>2018-08-14T14:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18754#M1440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Make sure both GWs have&amp;nbsp;your GW (or GWs if it is a cluster) have both default routes configured on OS level. Use WebUI or clish to setup. WIth clish, do not forget to type in "save config" command.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 14:54:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18754#M1440</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-14T14:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18755#M1441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Valeri.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I didnt understand. Gateway is in standalone deployment and not part of cluster. Are you talking about configure through clish? What is the command to add default route through clish. If i add the route, will it remain permanent in routing table. And isp redundancy will also work in case in load sharing one 1 isp goes down then there will be only one default route pointing to another Isp. As soon as isp is up again routing table will have both routes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 15:09:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18755#M1441</guid>
      <dc:creator>Ankur_Datta1</dc:creator>
      <dc:date>2018-08-14T15:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18756#M1442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Before we go any further, are you using the same NIC to connect to both ISPs?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 15:16:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18756#M1442</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-14T15:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18757#M1443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No. On gateway ISP links are connected to two different interfaces.&amp;nbsp; Example : ISP - A on eth1 and ISP - B on eth2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 15:21:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18757#M1443</guid>
      <dc:creator>Ankur_Datta1</dc:creator>
      <dc:date>2018-08-14T15:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18758#M1444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perfect, that is the requirement for ISP redundancy. Now, make sure on OS level each of the interfaces has a default route defined for it. Which version of software are you using?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 15:33:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18758#M1444</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-14T15:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18759#M1445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are on Gaia, use&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;set static-route default nexthop gateway address&amp;nbsp; on|off &lt;/PRE&gt;&lt;P&gt;to add or delete a static route.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Always conclude with&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;save config&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 15:40:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18759#M1445</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-14T15:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18760#M1446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I Ran same command to configure defaul route to back isp and done save config as well. This was ran in normal prompt where we can see configuration or configure using set command.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further if i test ISP redundancy, i remove cable from port eth1 (primary isp) routing table shows default route to backup isp. But when i plug cable back another default route dont show in routing table. I need to check what route goes missing( the configured through cli or web gui) and will update you.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 15:48:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18760#M1446</guid>
      <dc:creator>Ankur_Datta1</dc:creator>
      <dc:date>2018-08-14T15:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18761#M1447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ankur,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any luck finding the right answer? I am having the same issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Mahir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Feb 2019 14:44:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/18761#M1447</guid>
      <dc:creator>Mahir_Ali_Ahmed</dc:creator>
      <dc:date>2019-02-28T14:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy - 2 default route pointing to different ISP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/119562#M16910</link>
      <description>&lt;P&gt;May be check on &lt;SPAN&gt;sk95249&amp;nbsp;How to configure multiple routes to the same network host in Gaia OS?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 May 2021 11:40:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-2-default-route-pointing-to-different-ISP/m-p/119562#M16910</guid>
      <dc:creator>denis-stl</dc:creator>
      <dc:date>2021-05-27T11:40:06Z</dc:date>
    </item>
  </channel>
</rss>

