<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: static nat single host to multiple ISP IP's for failover in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/145946#M23101</link>
    <description>&lt;P&gt;for incoming connections only (your webserver will be reachable via 2 external IPs) you have to define two manual NAT rules&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Screenshot 2022-04-11 105617.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16000i9F7DE10E037F4B61/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-04-11 105617.png" alt="Screenshot 2022-04-11 105617.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Apr 2022 08:56:55 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2022-04-11T08:56:55Z</dc:date>
    <item>
      <title>static nat single host to multiple ISP IP's for failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/145781#M23047</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to NAT single host statically to 2 different ISP for failover purpose for publicly hosted servers . Is it possible using manual NAT? Guide me on this... Thanks in advance&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 03:52:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/145781#M23047</guid>
      <dc:creator>Sagar_Manandhar</dc:creator>
      <dc:date>2022-04-08T03:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: static nat single host to multiple ISP IP's for failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/145785#M23048</link>
      <description>&lt;P&gt;Using manual NAT this should be straight forward, are you using the ISP redundancy feature?&lt;/P&gt;
&lt;P&gt;The only caveat that I can think of otherwise is that you'll likely need some PBR (source routing) or similar for the return traffic.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 06:20:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/145785#M23048</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-04-08T06:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: static nat single host to multiple ISP IP's for failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/145798#M23049</link>
      <description>&lt;P&gt;With ISP redundancy enabled the return traffic will be no problem. Outgoing return traffic is sent via the same interface from&amp;nbsp; incoming.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 08:22:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/145798#M23049</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-04-08T08:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: static nat single host to multiple ISP IP's for failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/145941#M23099</link>
      <description>&lt;P&gt;we are using load sharing in our environment and PBR doesn't work in this scenario. Is their any alternative solution for this?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 08:19:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/145941#M23099</guid>
      <dc:creator>Sagar_Manandhar</dc:creator>
      <dc:date>2022-04-11T08:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: static nat single host to multiple ISP IP's for failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/145946#M23101</link>
      <description>&lt;P&gt;for incoming connections only (your webserver will be reachable via 2 external IPs) you have to define two manual NAT rules&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Screenshot 2022-04-11 105617.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16000i9F7DE10E037F4B61/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-04-11 105617.png" alt="Screenshot 2022-04-11 105617.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Apr 2022 08:56:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/145946#M23101</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-04-11T08:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: static nat single host to multiple ISP IP's for failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/146154#M23158</link>
      <description>&lt;P&gt;Is there any solution for outgoing traffic so that if single nat fail, nat automatically switch to another in load sharing environment.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 03:49:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/146154#M23158</guid>
      <dc:creator>Sagar_Manandhar</dc:creator>
      <dc:date>2022-04-13T03:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: static nat single host to multiple ISP IP's for failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/146157#M23160</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9011"&gt;@Sagar_Manandhar&lt;/a&gt;&amp;nbsp;maybee you can provide more details of your use case.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With the shown NAT rules your internal webserver can be reached via the IP address from ISP_A and via the IP address from ISP_B. Both are active at all the time. The return traffic from your webserver will be routed through the same ISP as it coming in. An&amp;nbsp;incoming packet via ISP_A will be forwarded to your webserver and the return packet will be send out via ISP_A. This is how ISP redundancy works.&lt;/P&gt;
&lt;P&gt;You have to define both external IPs in the external DNS for name resolution of your webserver. In case one of the ISPs is failing the failing ISPs external IP address has to be removed from this DNS record. If you want to have an automatic change of the DNS records you can use DNS proxy feature of ISP redundancy.&lt;/P&gt;
&lt;P&gt;But I would prefer an external solution to check the availability of your ISPs and route the traffoc to the right incoming site. Something like Azure Traffic Manger as an example, they can probe your webserver via both ISPs and change DNS following the availability.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 06:39:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/146157#M23160</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-04-13T06:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: static nat single host to multiple ISP IP's for failover</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/146160#M23161</link>
      <description>&lt;P&gt;Agreed, the problem statement should be clarified. It still remains unclear if ISP redundancy (check point feature as different to the concept is being used here).&lt;/P&gt;
&lt;P&gt;Provider independent addressing and a GTM solution would certainly help!&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 06:58:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/static-nat-single-host-to-multiple-ISP-IP-s-for-failover/m-p/146160#M23161</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-04-13T06:58:13Z</dc:date>
    </item>
  </channel>
</rss>

