<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISP Redundancy in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy/m-p/133334#M19829</link>
    <description>&lt;P&gt;Team,&lt;/P&gt;&lt;P&gt;we have a DMZ cluster on our active site and DR site has standalone. we are going to add DR site to the existing cluster&lt;/P&gt;&lt;P&gt;what we do today is if the active site ISP goes down we turn on the WAN/ISP/External interface on the DR site Standalone though which then our internet traffic works&lt;/P&gt;&lt;P&gt;ISP at both the locations is same and it provides same CIDR range at both locations for ex 123.123.123.128/29 at both locations and our ISP does not do active standby it is active and continuously pass traffic&amp;nbsp; so that's the reason we turn the interface down so that traffic duplication should not take place.&lt;/P&gt;&lt;P&gt;when we add DR site member to active site cluster we want all the interfaces to be up all the time and checkpoint do ISP redundance and make one ISP standby and one ACTIVE&lt;/P&gt;&lt;P&gt;what I thought is having all the members external interface connected to switch and then ISP from both the locations connect to that switch as gateway is same for both the locations&lt;/P&gt;&lt;P&gt;i need help with best approach to do this&lt;/P&gt;</description>
    <pubDate>Fri, 05 Nov 2021 20:30:54 GMT</pubDate>
    <dc:creator>smohammed</dc:creator>
    <dc:date>2021-11-05T20:30:54Z</dc:date>
    <item>
      <title>ISP Redundancy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy/m-p/133334#M19829</link>
      <description>&lt;P&gt;Team,&lt;/P&gt;&lt;P&gt;we have a DMZ cluster on our active site and DR site has standalone. we are going to add DR site to the existing cluster&lt;/P&gt;&lt;P&gt;what we do today is if the active site ISP goes down we turn on the WAN/ISP/External interface on the DR site Standalone though which then our internet traffic works&lt;/P&gt;&lt;P&gt;ISP at both the locations is same and it provides same CIDR range at both locations for ex 123.123.123.128/29 at both locations and our ISP does not do active standby it is active and continuously pass traffic&amp;nbsp; so that's the reason we turn the interface down so that traffic duplication should not take place.&lt;/P&gt;&lt;P&gt;when we add DR site member to active site cluster we want all the interfaces to be up all the time and checkpoint do ISP redundance and make one ISP standby and one ACTIVE&lt;/P&gt;&lt;P&gt;what I thought is having all the members external interface connected to switch and then ISP from both the locations connect to that switch as gateway is same for both the locations&lt;/P&gt;&lt;P&gt;i need help with best approach to do this&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 20:30:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy/m-p/133334#M19829</guid>
      <dc:creator>smohammed</dc:creator>
      <dc:date>2021-11-05T20:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy/m-p/133416#M19851</link>
      <description>&lt;P&gt;I'm curious how the ISP knows to route traffic to one location versus the other if both sites have the same block.&lt;BR /&gt;Seems like that could be solved by using Dynamic Routing or similiar.&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 02:47:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy/m-p/133416#M19851</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-08T02:47:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy/m-p/133517#M19857</link>
      <description>&lt;P&gt;I am not sure what ISP is doing on their end. when you say Dynamic routing what do you suggest as an example.&amp;nbsp; currently on the default route on the members we have given gateway defined, can we define interface instead and does checkpoint has some feature to have active standby on the interface level&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 15:06:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy/m-p/133517#M19857</guid>
      <dc:creator>smohammed</dc:creator>
      <dc:date>2021-11-08T15:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy/m-p/133528#M19861</link>
      <description>&lt;P&gt;If you define an interface as the default route (versus a specific IP address), that will mean an ARP entry will be required for every server you connect to on the Internet.&lt;BR /&gt;This will cause the ARP table to full up and was problematic even&amp;nbsp;on my home network.&lt;BR /&gt;It would fail spectacularly in an enterprise environment.&lt;/P&gt;
&lt;P&gt;Dynamic Routing means using BGP or OSPF, which if you're not using it already may not necessarily be an effective strategy.&lt;BR /&gt;You really need to find out what the ISP is doing here.&lt;BR /&gt;That said, if it's just a matter of using a different next hop for the default route, you can set two of them and configure different priorities and a monitored address for each one.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-11-08 at 8.19.59 AM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14205iA9B00C2671E9E638/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2021-11-08 at 8.19.59 AM.png" alt="Screen Shot 2021-11-08 at 8.19.59 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Nov 2021 16:23:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy/m-p/133528#M19861</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-11-08T16:23:19Z</dc:date>
    </item>
  </channel>
</rss>

