<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISP redundancy link health status in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204914#M38629</link>
    <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Hope someone can clarify this for me. Are there any commands to run on CP side that would show actual health of the ISP link? Client has ISPR configured, but they had been having issues lately when random users not being able to RDP or losing pings to some internal servers when connected to primary link, but if they connect to 2nd isp link, all works fine.&lt;/P&gt;
&lt;P&gt;TAC provided cpstat fw and sv monitor options to check this, but thats not helpful here at all, it simply shows whether links are up or down.&lt;/P&gt;
&lt;P&gt;Any other commands we could utilize to check say status of the link in the last 30 days?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Fri, 02 Feb 2024 20:47:33 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-02-02T20:47:33Z</dc:date>
    <item>
      <title>ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204914#M38629</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Hope someone can clarify this for me. Are there any commands to run on CP side that would show actual health of the ISP link? Client has ISPR configured, but they had been having issues lately when random users not being able to RDP or losing pings to some internal servers when connected to primary link, but if they connect to 2nd isp link, all works fine.&lt;/P&gt;
&lt;P&gt;TAC provided cpstat fw and sv monitor options to check this, but thats not helpful here at all, it simply shows whether links are up or down.&lt;/P&gt;
&lt;P&gt;Any other commands we could utilize to check say status of the link in the last 30 days?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 20:47:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204914#M38629</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-02T20:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204917#M38631</link>
      <description>&lt;P&gt;Does the link flip-over? How does ISPR check if the link is healhty, does it ping only the default gateway?&lt;/P&gt;
&lt;P&gt;If you only ping the DG it is not a proper health check, I always recommended to check the health of the IP after the DG. This will show in a traceroute&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But on CLI it is indeed cpstat fw, to see if it is active/backup or down. Same output I think you can see in cpview.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you want history if link failures they always have been logged in smartlog if you search for 'alerts'&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 21:19:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204917#M38631</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-02-02T21:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204918#M38632</link>
      <description>&lt;P&gt;There is never a failover, no. Ping to DG is fine, no issues there. I will check for alerts.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 21:22:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204918#M38632</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-02T21:22:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204920#M38633</link>
      <description>&lt;P&gt;Ping to DG is a not a solid way to test an internet connection. Best would be to monitor extra hop (maybe DNS from ISP?) or second IP in traceroute. Make sure to make static route for this next hop ip to force it via the correct ISP link.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 21:42:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204920#M38633</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-02-02T21:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204923#M38635</link>
      <description>&lt;P&gt;Trust me, there are no issues with DG or the link, Im 100% positive. Let me see what TAC guy gives Monday during remote.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 22:24:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204923#M38635</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-02T22:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204924#M38636</link>
      <description>&lt;P&gt;So from check point point of view what is the issue? If you think link is OK but users complain maybe the link is just full? Maybe check cpview history if the link is full up or down. Check peak and compare what the isp gives for speed&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 22:32:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204924#M38636</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-02-02T22:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204925#M38637</link>
      <description>&lt;P&gt;Thats what we are trying to find out IF it is indeed CP issue lol&lt;/P&gt;
&lt;P&gt;Thats why I asked if there are good commands to run that would show the health historically. I looked through cpview, but cant find good option, unless I missed it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 22:34:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204925#M38637</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-02T22:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204926#M38638</link>
      <description>&lt;P&gt;The network part where you can see the interfaces and the mbps tx and rx. Check historical if you see full isp link.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 22:50:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204926#M38638</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-02-02T22:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204927#M38639</link>
      <description>&lt;P&gt;K, thank you...will check Monday.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 02 Feb 2024 22:51:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204927#M38639</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-02T22:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204991#M38649</link>
      <description>&lt;P&gt;Just had a quick look on customer's master fw and I dont see anything there related to ISP links. I do see stats for eth1, which represents, if you will, their primary ISP link, but no obvious issues that I can tell. Anyway, let me see what TAC guy says tomorrow.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2024 19:15:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/204991#M38649</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-04T19:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/205070#M38662</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;Just had remote with Tier3 guy from DTAC and he said command I gave fw -d isp_link to debug is the best, but otherwise, they dont sadly have a general IPS link health check commands. He advised to troubleshoot this when issue when someone is havinng the problem when connected to primary ISP link, so Im totally okay with that.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Anyd&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 15:33:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/205070#M38662</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-05T15:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/206015#M38910</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;did you get any results, or have you found a procedure to track down the ISP redundancy issue?&lt;/P&gt;&lt;P&gt;We have two ISP links and when the primary link is active, it's showing the same behavior you're reporting, but only for FTP traffic and ICMP. The provider is promising that the line is okay. Swapping to the secondary, everything is fine.&lt;/P&gt;&lt;P&gt;The people on site are questioning the 6400, because another site in the same city and the same provider using a 6600 do not have problems at all.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Rgds from Germany&lt;BR /&gt;--Guido&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 07:00:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/206015#M38910</guid>
      <dc:creator>Guido_Marx</dc:creator>
      <dc:date>2024-02-14T07:00:19Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/206060#M38921</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Not really, sorry : - (. TAC guy said you can go to cpview, software-blades, then vpn, and if you scroll down, then you see link failures option,but again, that ONLY shows you if link ever failed, NOT the actual health.&lt;/P&gt;
&lt;P&gt;Little disappointing there is no better way, but hey, as that cheesy saying goes, it is what it is haha. Maybe this becomes available in R82, no clue.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 12:17:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/206060#M38921</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-14T12:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/206077#M38924</link>
      <description>&lt;P&gt;consider replace ISPR with our Quantum SD-WAN.&lt;/P&gt;
&lt;P&gt;with Quantum SD-WAN you will have clear visibility on the probing for each link with full sla results in real time and history, per steering / rule&amp;nbsp; (traffic), clear events on link swaps, and much more functionality &amp;amp; granularity.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 13:12:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/206077#M38924</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2024-02-14T13:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: ISP redundancy link health status</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/206083#M38925</link>
      <description>&lt;P&gt;I get what you are saying, but thats sadly not an option at the moment.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 14 Feb 2024 13:45:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-redundancy-link-health-status/m-p/206083#M38925</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-14T13:45:51Z</dc:date>
    </item>
  </channel>
</rss>

