<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISP Redudancy R80.40 for Network Object in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redudancy-R80-40-for-Network-Object/m-p/158126#M27541</link>
    <description>&lt;P&gt;Hello All,&lt;BR /&gt;&lt;BR /&gt;Btw currently im in development for testing ISP redundancy for our internal network using #CP 6900 R80.40 Cluster mode&lt;BR /&gt;as, documentation ISP redundancy is working with object using automatic hide nat. im already testing and its working for connection and swing between each ISP like bellow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Host ISP.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17897i3A357A7EECDCCC44/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Host ISP.png" alt="Host ISP.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; But somehow, we have plan to use Internet ISP on CP for direct internet user, so i try to use this hide nat for all internal net like bellow, but when i test connection on pc, the connection is not working&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Host Subnet.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17896iEA0E9CCD1AFC48A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Host Subnet.png" alt="Host Subnet.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; Is there anyone know, and maybe have some advice, how to set isp redundancy for outgoing connection for some subnet/network ? Thanks in advance&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Sep 2022 08:03:38 GMT</pubDate>
    <dc:creator>rdinata01</dc:creator>
    <dc:date>2022-09-27T08:03:38Z</dc:date>
    <item>
      <title>ISP Redudancy R80.40 for Network Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redudancy-R80-40-for-Network-Object/m-p/158126#M27541</link>
      <description>&lt;P&gt;Hello All,&lt;BR /&gt;&lt;BR /&gt;Btw currently im in development for testing ISP redundancy for our internal network using #CP 6900 R80.40 Cluster mode&lt;BR /&gt;as, documentation ISP redundancy is working with object using automatic hide nat. im already testing and its working for connection and swing between each ISP like bellow.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Host ISP.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17897i3A357A7EECDCCC44/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Host ISP.png" alt="Host ISP.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; But somehow, we have plan to use Internet ISP on CP for direct internet user, so i try to use this hide nat for all internal net like bellow, but when i test connection on pc, the connection is not working&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Host Subnet.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17896iEA0E9CCD1AFC48A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Host Subnet.png" alt="Host Subnet.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; Is there anyone know, and maybe have some advice, how to set isp redundancy for outgoing connection for some subnet/network ? Thanks in advance&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 08:03:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redudancy-R80-40-for-Network-Object/m-p/158126#M27541</guid>
      <dc:creator>rdinata01</dc:creator>
      <dc:date>2022-09-27T08:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redudancy R80.40 for Network Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redudancy-R80-40-for-Network-Object/m-p/158127#M27542</link>
      <description>&lt;P&gt;Manual NAT Hide rules will not work with ISP redundancy, this is mentioned in the documentation and also in&amp;nbsp;&lt;SPAN&gt;sk61692. Define your NET_10.0.0.0 as an object (you did) and set up automatic NAT hide behind the GW for it.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 08:18:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redudancy-R80-40-for-Network-Object/m-p/158127#M27542</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-27T08:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redudancy R80.40 for Network Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redudancy-R80-40-for-Network-Object/m-p/158133#M27544</link>
      <description>&lt;P&gt;Hi thanks &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt; thanks for your advice,&lt;BR /&gt;Btw im already set hide nat for the subnet , but, the connection only working with isp defined on IPv4 Cluster IPS, let say, ISP A with ip 103.111 , and im tes isp redundancy wih two isp, ISP A and ISP B # im setting ISP B, is high priority than ISP A, but when i check on user, client still connected to ISP A, and when i shutdown ISP A, the connection is down. Is there any additional configuration ? or should i set ISP A as primary, since i set IPv4 cluster public using ISP A. Thanks&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Object.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17900i59B196FE376A2BDB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Object.png" alt="Object.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;###&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="ISP Conf.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17901iB94A5565429D8ADB/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISP Conf.png" alt="ISP Conf.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;###&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 08:48:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redudancy-R80-40-for-Network-Object/m-p/158133#M27544</guid>
      <dc:creator>rdinata01</dc:creator>
      <dc:date>2022-09-27T08:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redudancy R80.40 for Network Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redudancy-R80-40-for-Network-Object/m-p/158135#M27545</link>
      <description>&lt;P&gt;Uh, you don't like simple life, you are running a Load Sharing config &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Did you remove the manual NAT rule mentioned above? If yes, and if internet connectivity drops after turning of ISP1, check for any routes on the GW for NET_10 object. If you do not have those, open a TAC case, this should work as described above.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 09:03:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redudancy-R80-40-for-Network-Object/m-p/158135#M27545</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-27T09:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redudancy R80.40 for Network Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redudancy-R80-40-for-Network-Object/m-p/158136#M27546</link>
      <description>&lt;P&gt;Also, look into&amp;nbsp;&lt;SPAN&gt;sk105239, this is your simptom. Most probably a config issue.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 09:05:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redudancy-R80-40-for-Network-Object/m-p/158136#M27546</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-27T09:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redudancy R80.40 for Network Object</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redudancy-R80-40-for-Network-Object/m-p/158137#M27547</link>
      <description>&lt;P&gt;haha&lt;BR /&gt;Yes im running load load sharing due to we want to focus our internet user direct via ISP B, so we set 75% and 25% on ISP A for remote access users. for manual nat we already deleted too&lt;BR /&gt;&lt;BR /&gt;and btw thanks for your time, we will check and test it again durring next mw&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 09:17:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redudancy-R80-40-for-Network-Object/m-p/158137#M27547</guid>
      <dc:creator>rdinata01</dc:creator>
      <dc:date>2022-09-27T09:17:54Z</dc:date>
    </item>
  </channel>
</rss>

