<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBR help please in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229117#M44145</link>
    <description>&lt;P&gt;Create an Action Table specifying ISP2's default route.&lt;BR /&gt;Create a policy rule that references this table something like below.&lt;BR /&gt;Only the source(s) specified will be routed to ISP2.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28023iCF6D8330BC47FDAC/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Oct 2024 15:40:37 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-10-07T15:40:37Z</dc:date>
    <item>
      <title>PBR help please</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229083#M44141</link>
      <description>&lt;P&gt;Dear friends i have never done PBR in Checkpoint so i need help suggestions for this concrete question.&lt;/P&gt;&lt;P&gt;I have read the SK's so i have some kind of understanding.&lt;/P&gt;&lt;P&gt;What baffles me is as you see in attach i have one internal network that should communicate with DC and it does.&lt;/P&gt;&lt;P&gt;Now we got second ISP ISP2 on the drawing,&amp;nbsp; i&amp;nbsp; want to send all internet traffic from that 1.1.1.1 LAN to that ISP2.&lt;/P&gt;&lt;P&gt;all other networks are going to internet to ISP1.&lt;/P&gt;&lt;P&gt;i have in static routes 0.0.0.0 next hop ISP1&lt;/P&gt;&lt;P&gt;and for the communication with DC i have x.x.x.x next hop some internal gw.&lt;/P&gt;&lt;P&gt;everything works .&lt;/P&gt;&lt;P&gt;Now i want to send\receive&amp;nbsp; internet traffic from 1.1.1.1 to ISP2 and not to disrupt communication with DC.&lt;/P&gt;&lt;P&gt;Hope i was clear and simple.&lt;/P&gt;&lt;P&gt;thanks in advance &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 13:29:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229083#M44141</guid>
      <dc:creator>Nenad_Odic</dc:creator>
      <dc:date>2024-10-07T13:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: PBR help please</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229117#M44145</link>
      <description>&lt;P&gt;Create an Action Table specifying ISP2's default route.&lt;BR /&gt;Create a policy rule that references this table something like below.&lt;BR /&gt;Only the source(s) specified will be routed to ISP2.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28023iCF6D8330BC47FDAC/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Oct 2024 15:40:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229117#M44145</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-07T15:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: PBR help please</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229160#M44149</link>
      <description>&lt;P&gt;Thanks for help,&lt;/P&gt;&lt;P&gt;i have tried this kind of settings but than my communication from 1.1.1.1 to DC is broken .Internet works.&lt;/P&gt;&lt;P&gt;so do i have to have more than one rule or table regarding the dc communication?&lt;/P&gt;&lt;P&gt;Please help&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 08:31:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229160#M44149</guid>
      <dc:creator>Nenad_Odic</dc:creator>
      <dc:date>2024-10-08T08:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: PBR help please</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229163#M44150</link>
      <description>&lt;P&gt;I would suggest to contact CP TAC to get this resolved!&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 10:06:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229163#M44150</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-10-08T10:06:05Z</dc:date>
    </item>
    <item>
      <title>Re: PBR help please</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229184#M44154</link>
      <description>&lt;P&gt;It's been a while, but for as far as I can remember, PBR takes absolute precedence over all other routes.&amp;nbsp; So if you create a Policy Based Route that sends all traffic from 1.1.1.1 to ISP2, you should add another PBR for the traffic from 1.1.1.1 towards DC as well.&lt;/P&gt;&lt;P&gt;Make sure to take the Hide-NAT for your internet traffic into account as well, as this will most probably differ between ISP1 and ISP2.&lt;/P&gt;&lt;P&gt;Just my two cents...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 13:01:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229184#M44154</guid>
      <dc:creator>PeterL</dc:creator>
      <dc:date>2024-10-08T13:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: PBR help please</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229240#M44160</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;You need to create two PBR rules in your PBR configuration and in the order below.&lt;BR /&gt;&lt;BR /&gt;1. Traffic from 1.1.1.1 to DC needs to use the routing table (Main Table via internal gateway)&lt;BR /&gt;2. Traffic from 1.1.1.1 to internet needs to use the ISP2 Table.&lt;BR /&gt;&lt;BR /&gt;If traffic goes to the DC, the first rule is hit. All other traffic is going via IPS2.&lt;BR /&gt;&lt;BR /&gt;Maybe more rules are needed to suit your routing requirements.&lt;BR /&gt;&lt;BR /&gt;Good luck.&lt;BR /&gt;&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Wed, 09 Oct 2024 08:46:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229240#M44160</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2024-10-09T08:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: PBR help please</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229472#M44195</link>
      <description>&lt;P&gt;Thanks to you all i have managed to setup this to work .&lt;/P&gt;&lt;P&gt;There were some shenanigan's with the NAT but now it is solved .&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2024 13:49:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PBR-help-please/m-p/229472#M44195</guid>
      <dc:creator>Nenad_Odic</dc:creator>
      <dc:date>2024-10-11T13:49:04Z</dc:date>
    </item>
  </channel>
</rss>

