<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISP redundancy Cluster in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-Cluster/m-p/185953#M34204</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I have some questions regarding ISP redundancy.&lt;/P&gt;&lt;P&gt;Currently, I have Checkpoint running production version R81.10 with the cluster active/stanby.&lt;BR /&gt;On the cluster box, have a configuration like below&amp;nbsp;&lt;BR /&gt;- two ISP links on gateway&lt;BR /&gt;- dynamic routing OSPF protocol&lt;BR /&gt;- site-to-site vpn&amp;nbsp;&lt;BR /&gt;- remote access vpn&lt;BR /&gt;- incoming and outgoing nat&lt;/P&gt;&lt;P&gt;and just want to know if I would like to enable ISP redundancy on the existing cluster box&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are the challenges to achieving this need?&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;P&gt;mgl&lt;/P&gt;</description>
    <pubDate>Sat, 08 Jul 2023 06:24:54 GMT</pubDate>
    <dc:creator>leangm</dc:creator>
    <dc:date>2023-07-08T06:24:54Z</dc:date>
    <item>
      <title>ISP redundancy Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-Cluster/m-p/185953#M34204</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I have some questions regarding ISP redundancy.&lt;/P&gt;&lt;P&gt;Currently, I have Checkpoint running production version R81.10 with the cluster active/stanby.&lt;BR /&gt;On the cluster box, have a configuration like below&amp;nbsp;&lt;BR /&gt;- two ISP links on gateway&lt;BR /&gt;- dynamic routing OSPF protocol&lt;BR /&gt;- site-to-site vpn&amp;nbsp;&lt;BR /&gt;- remote access vpn&lt;BR /&gt;- incoming and outgoing nat&lt;/P&gt;&lt;P&gt;and just want to know if I would like to enable ISP redundancy on the existing cluster box&amp;nbsp;&lt;/P&gt;&lt;P&gt;What are the challenges to achieving this need?&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards,&lt;/P&gt;&lt;P&gt;mgl&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jul 2023 06:24:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-Cluster/m-p/185953#M34204</guid>
      <dc:creator>leangm</dc:creator>
      <dc:date>2023-07-08T06:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-Cluster/m-p/185958#M34205</link>
      <description>&lt;P&gt;ISP redundancy has quite a few limitations, mostly around SecureXL functionality. I would advise you to review those before making your decision.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jul 2023 08:14:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-Cluster/m-p/185958#M34205</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-07-08T08:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-Cluster/m-p/185974#M34212</link>
      <description>&lt;P&gt;I have this running and it works pretty well.&amp;nbsp; Remember you still only have one "Default" gateway - e.g ISP-1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We statically route some destinations out of ISP-2.&amp;nbsp; We also use PBR to route some stuff via ISP-2.&lt;/P&gt;&lt;P&gt;ISP Redundancy relies on the ability (or not) to ping upstream IP's to tell if the line is up and healthy or not, and therefore whether to fail over or not.&amp;nbsp; So remember, if both ISP circuits are from the same telco and that telco have an issue, it could affect the ability for both of the firewall's ISP lines to determine which is healthiest.&amp;nbsp; I experienced this rather shaky meltdown recently and basically had little option but to wait for the telco to fix their issue.&amp;nbsp; So for best resilience you want to use different telco's and ensure their cables in the ground don't run up the same street to your building...&amp;nbsp; You know, the street that has a JCB about to start digging the road up, and both of your ISP lines with it&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jul 2023 22:40:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-Cluster/m-p/185974#M34212</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2023-07-08T22:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-Cluster/m-p/185976#M34214</link>
      <description>&lt;P&gt;what did you mean by review?&lt;/P&gt;&lt;P&gt;the services running on Checkpint already describe here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2023 05:47:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-Cluster/m-p/185976#M34214</guid>
      <dc:creator>leangm</dc:creator>
      <dc:date>2023-07-09T05:47:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy Cluster</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-Cluster/m-p/185989#M34219</link>
      <description>&lt;P&gt;What&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;was suggesting was to review the relevant documentation.&lt;BR /&gt;However, I think most of those limitations have been resolved in current releases.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jul 2023 15:33:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-Cluster/m-p/185989#M34219</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-09T15:33:17Z</dc:date>
    </item>
  </channel>
</rss>

