<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/243165#M47232</link>
    <description>&lt;P&gt;Glad we can help mate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 06 Mar 2025 12:48:35 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-03-06T12:48:35Z</dc:date>
    <item>
      <title>Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242535#M47113</link>
      <description>&lt;P&gt;Network Topology:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISP Rededundency DYNAMIC OBJECT.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29735iE40C1E44DA237FF0/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISP Rededundency DYNAMIC OBJECT.jpg" alt="ISP Rededundency DYNAMIC OBJECT.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;ISP Redundancy : &lt;STRONG&gt;Active/Standby&lt;/STRONG&gt; Mode&lt;/P&gt;
&lt;P&gt;Source: Host_A IP :&amp;nbsp;&lt;STRONG&gt;11.201.6.171&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;Host_B IP :&amp;nbsp;&lt;STRONG&gt;11.201.6.172&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Destination is &lt;STRONG&gt;XYZ Server&lt;/STRONG&gt; IP:&amp;nbsp;&lt;STRONG&gt;142.250.205.238&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ISP-1 NAT Public IP&lt;/STRONG&gt;: 116.113.114.25 (From pool)&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ISP-2 NAT Public IP&lt;/STRONG&gt;: 58.143.112.130 (From Pool)&lt;/P&gt;
&lt;P&gt;I created a manual NAT rule for this like below&lt;/P&gt;
&lt;P&gt;Outbound Connection we need:&lt;/P&gt;
&lt;TABLE width="671"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="67.2656px" height="69px"&gt;NAT Rule No&lt;/TD&gt;
&lt;TD width="100.781px" height="69px"&gt;Original Source&lt;/TD&gt;
&lt;TD width="129.25px" height="69px"&gt;Original Destination&lt;/TD&gt;
&lt;TD width="67.1094px" height="69px"&gt;Original Service&lt;/TD&gt;
&lt;TD width="115.844px" height="69px"&gt;Translate Source&lt;/TD&gt;
&lt;TD width="91.6719px" height="69px"&gt;Translate Destination&lt;/TD&gt;
&lt;TD width="98.0781px" height="69px"&gt;Translate Service&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="67.2656px" height="25px"&gt;1&lt;/TD&gt;
&lt;TD width="100.781px" height="25px"&gt;11.201.6.171&lt;/TD&gt;
&lt;TD width="129.25px" height="25px"&gt;142.250.205.238&lt;/TD&gt;
&lt;TD width="67.1094px" height="25px"&gt;https&lt;/TD&gt;
&lt;TD width="115.844px" height="25px"&gt;116.113.114.25&lt;/TD&gt;
&lt;TD width="91.6719px" height="25px"&gt;Original&lt;/TD&gt;
&lt;TD width="98.0781px" height="25px"&gt;Original&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="67.2656px" height="25px"&gt;2&lt;/TD&gt;
&lt;TD width="100.781px" height="25px"&gt;11.201.6.171&lt;/TD&gt;
&lt;TD width="129.25px" height="25px"&gt;142.250.205.238&lt;/TD&gt;
&lt;TD width="67.1094px" height="25px"&gt;https&lt;/TD&gt;
&lt;TD width="115.844px" height="25px"&gt;58.143.112.130&lt;/TD&gt;
&lt;TD width="91.6719px" height="25px"&gt;Original&lt;/TD&gt;
&lt;TD width="98.0781px" height="25px"&gt;Original&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="67.2656px" height="25px"&gt;3&lt;/TD&gt;
&lt;TD width="100.781px" height="25px"&gt;11.201.6.172&lt;/TD&gt;
&lt;TD width="129.25px" height="25px"&gt;142.250.205.238&lt;/TD&gt;
&lt;TD width="67.1094px" height="25px"&gt;https&lt;/TD&gt;
&lt;TD width="115.844px" height="25px"&gt;116.113.114.26&lt;/TD&gt;
&lt;TD width="91.6719px" height="25px"&gt;Original&lt;/TD&gt;
&lt;TD width="98.0781px" height="25px"&gt;Original&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="67.2656px" height="25px"&gt;4&lt;/TD&gt;
&lt;TD width="100.781px" height="25px"&gt;11.201.6.172&lt;/TD&gt;
&lt;TD width="129.25px" height="25px"&gt;142.250.205.238&lt;/TD&gt;
&lt;TD width="67.1094px" height="25px"&gt;https&lt;/TD&gt;
&lt;TD width="115.844px" height="25px"&gt;58.143.112.131&lt;/TD&gt;
&lt;TD width="91.6719px" height="25px"&gt;Original&lt;/TD&gt;
&lt;TD width="98.0781px" height="25px"&gt;Original&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Challenge :&amp;nbsp;&lt;/STRONG&gt;If &lt;STRONG&gt;ISP-1&lt;/STRONG&gt; once goes down then &lt;STRONG&gt;NAT Rule No-1&lt;/STRONG&gt; will always hit and its not going to hit the &lt;STRONG&gt;NAT&amp;nbsp;Rule No-2&lt;/STRONG&gt; and my internal system &lt;STRONG&gt;11.201.6.171&lt;/STRONG&gt; unable to reach the&amp;nbsp;&lt;STRONG&gt;XYZ Server&lt;/STRONG&gt; IP:&amp;nbsp;&lt;STRONG&gt;142.250.205.238.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;To resolved this issue We plan to implement Dynamic Object.&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Below is our POA&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;TABLE width="290"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="127.688px" height="25px"&gt;&lt;STRONG&gt;Object Name&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="161.312px" height="25px"&gt;&lt;STRONG&gt;Comment&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="127.688px" height="25px"&gt;DYN_ISP_A&lt;/TD&gt;
&lt;TD width="161.312px" height="25px"&gt;ISP 1&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="127.688px" height="25px"&gt;DYN_ISP_B&lt;/TD&gt;
&lt;TD width="161.312px" height="25px"&gt;ISP 2&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="249"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="116"&gt;&lt;STRONG&gt;Object Name&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="133"&gt;&lt;STRONG&gt;Comment&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;HOST_INTERNAL&lt;/TD&gt;
&lt;TD&gt;11.201.6.171&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;HOST_INTERNAL1&lt;/TD&gt;
&lt;TD&gt;11.201.6.172&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;TABLE width="290"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="128"&gt;&lt;STRONG&gt;Object Name&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="162"&gt;&lt;STRONG&gt;Comment&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;HOST_VALID_ISP_A&lt;/TD&gt;
&lt;TD&gt;116.113.114.19&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;HOST_VALID_ISP_B&lt;/TD&gt;
&lt;TD&gt;58.143.112.129&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Manual NAT Rule:&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;
&lt;TABLE width="736"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="116"&gt;&lt;STRONG&gt;Original Source&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="133"&gt;&lt;STRONG&gt;Original Destination&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="105"&gt;&lt;STRONG&gt;Original Service&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="128"&gt;&lt;STRONG&gt;Translate Source&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="141"&gt;&lt;STRONG&gt;Translate Destination&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="113"&gt;&lt;STRONG&gt;Translate Service&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;HOST_INTERNAL&lt;/TD&gt;
&lt;TD&gt;DYN_ISP_A&lt;/TD&gt;
&lt;TD&gt;https&lt;/TD&gt;
&lt;TD&gt;HOST_VALID_ISP_A&lt;/TD&gt;
&lt;TD&gt;Original&lt;/TD&gt;
&lt;TD&gt;Original&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;HOST_INTERNAL&lt;/TD&gt;
&lt;TD&gt;DYN_ISP_B&lt;/TD&gt;
&lt;TD&gt;https&lt;/TD&gt;
&lt;TD&gt;HOST_VALID_ISP_B&lt;/TD&gt;
&lt;TD&gt;Original&lt;/TD&gt;
&lt;TD&gt;Original&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;HOST_INTERNAL1&lt;/TD&gt;
&lt;TD&gt;DYN_ISP_A&lt;/TD&gt;
&lt;TD&gt;https&lt;/TD&gt;
&lt;TD&gt;HOST_VALID_ISP_A&lt;/TD&gt;
&lt;TD&gt;Original&lt;/TD&gt;
&lt;TD&gt;Original&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;HOST_INTERNAL1&lt;/TD&gt;
&lt;TD&gt;DYN_ISP_B&lt;/TD&gt;
&lt;TD&gt;https&lt;/TD&gt;
&lt;TD&gt;HOST_VALID_ISP_B&lt;/TD&gt;
&lt;TD&gt;Original&lt;/TD&gt;
&lt;TD&gt;Original&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Security Gateway / each member of ClusterXL, run the 'cpstop' command.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;1. Transfer the cpisp_update file to the both gateways ($FWDIR/bin/ directory) using scp tool.&lt;BR /&gt;2. Stop the Standby Member First (cpstop)&lt;BR /&gt;When running the commands below, we have to use the exact object name from SmartConsole&lt;BR /&gt;(case-sensitive).&lt;BR /&gt;[Expert@HostName]# dynamic_objects -n DYN_ISP_A&lt;BR /&gt;[Expert@HostName]# dynamic_objects -n DYN_ISP_B&lt;BR /&gt;[Expert@HostName]# dynamic_objects -o DYN_ISP_A -r 0.0.0.0 0.0.0.0 -a&lt;BR /&gt;[Expert@HostName]# dynamic_objects -o DYN_ISP_B -r 0.0.0.0 0.0.0.0 -a&lt;/P&gt;
&lt;P&gt;3. Convert the cpisp_update file script to Unix format (dos2unix&lt;BR /&gt;$FWDIR/bin/cpisp_update)&lt;BR /&gt;4. Make the script executable (chmod +x $FWDIR/bin/cpisp_update)&lt;BR /&gt;5. Start the service on Standby Member (cpstart)&lt;/P&gt;
&lt;P&gt;Repeat Steps 1-5 on the Other Gateway&lt;BR /&gt;We can see which ISP link is up with this command: tail -f /tmp/cpisp_state&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;File: $FWDIR/bin/cpisp_update : (Refer &lt;SPAN&gt;sk25152&lt;/SPAN&gt;)&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISP Red1.png" style="width: 699px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29736i7535CCC9A719D78A/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISP Red1.png" alt="ISP Red1.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Add the following configuration to have a Primary/Backup ISP solution (it will allow the Primary ISP to take back control after it is up again):&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ISP Red2.png" style="width: 556px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29737i183B8C6D688E4D08/image-size/large?v=v2&amp;amp;px=999" role="button" title="ISP Red2.png" alt="ISP Red2.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Challenges Question 1:&lt;/SPAN&gt;&lt;/STRONG&gt;&amp;nbsp; We already configured &lt;STRONG&gt;sk32073 (Configuring Cluster Addresses on Different Subnets) and its running on the production so is this going to impact the Dynamic Object implementation?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;Challenges Question 2:&lt;/SPAN&gt;&amp;nbsp; We also have a one internal server server communication and that routes towards the external sub-interface eth1-01.x and route is also created and its working fine but if I configured the Dynamic Object rule then I am sure its hit the access control rule and then NAT Rule-1 and the source 11.201.6.171 unable to reach to the Internal Server.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Its complicate and its running on a critical environment so please need all of your assistance will be Great.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Regards&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 11:44:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242535#M47113</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2025-02-27T11:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242574#M47114</link>
      <description>&lt;P&gt;Hey man,&lt;/P&gt;
&lt;P&gt;Since you asked me about this post on zoom remote, I really believe best thing to do is open TAC case, since they may need to provide updated ISPR script. Thats what was given to my colleague and I while back when we had similar issue. Personally, I would be super careful updating this file. Just make sure if you do that you back it up first, so its easy to revert later.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 17:23:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242574#M47114</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-27T17:23:58Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242608#M47120</link>
      <description>&lt;P&gt;Did you try to use Zones instead?&lt;/P&gt;
&lt;P&gt;The fact that we need to use script into a FW for operation like this it sounds ridiculous to me&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 21:22:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242608#M47120</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2025-02-27T21:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242614#M47125</link>
      <description>&lt;P&gt;Now that I think about it, sounds logical.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 00:39:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242614#M47125</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T00:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242615#M47126</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;Message me directly Friday and we can do zoom, I will have time to check. If 12 pm est is late, we can do say 8.30 am est, which is 7 pm for you, if that works?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 00:51:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242615#M47126</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T00:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242643#M47130</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&amp;nbsp;Thank you so much for the wonderful discussion we had yesterday&amp;nbsp; and last week —it truly left an impression on me.&lt;/P&gt;
&lt;P&gt;I’m genuinely inspired by how you generously offer your valuable time to help others, diving into their challenges and sharing the best solutions with such care. The Checkpoint community is truly remarkable; being part of this forum and supporting one another reflects a beautiful spirit of curiosity and kindness.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 11:05:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242643#M47130</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2025-02-28T11:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242647#M47132</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;for your kind words. I know I may not be nearly as smart as lots of other people on here, but I will ALWAYS do my best to help.&lt;/P&gt;
&lt;P&gt;Have a nice weekend and be free to reach out any time you are ready to check this further.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 11:48:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242647#M47132</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T11:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242653#M47135</link>
      <description>&lt;P&gt;Btw, if you wanted to give me some more details about this, we can have zoom remote, not an issue. Im good now for another 55 mins or same time as yesterday.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 13:06:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242653#M47135</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T13:06:50Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242668#M47145</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your reply, yes will connect on zoom remote as yesterday time.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 14:15:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242668#M47145</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2025-02-28T14:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242669#M47146</link>
      <description>&lt;P&gt;Awesome! I will send you zoom directly then.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 14:18:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242669#M47146</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T14:18:12Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242710#M47156</link>
      <description>&lt;P&gt;Hey man,&lt;/P&gt;
&lt;P&gt;Sent you link directly.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 17:03:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242710#M47156</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T17:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242720#M47165</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;
&lt;P&gt;Just to update quick...did zoom with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;and we went over below link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk25152" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk25152&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I explained that in my view, as long as routes are correct, ISPR should function normally if active link fails, since it would not be used for VPN tunnels. I also showed the guys basic example for health check IP in my Fortinet lab with FortiSASE setup, though to me, as I explained, I would certainly try simulate all this to best of my ability in the lab, since asking the customer to do it and hope for the best, definitely not a good idea, as it may turn into hours long remote with TAC doing debugs/trhoubleshooting.&lt;/P&gt;
&lt;P&gt;Anyway,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;, if you have other questions/doubts, let me know. I used to have ISPR configured in our Azure lab, but had to get rid of it, since we have to built another Harmony SASE lab for a customer.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 17:52:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/242720#M47165</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T17:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/243156#M47229</link>
      <description>&lt;P class="break-words"&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="break-words"&gt;I just wanted to reach out directly to say a heartfelt &lt;STRONG&gt;thank you&lt;/STRONG&gt; for taking the time last Friday to join us for that Zoom session. Your generosity with your expertise and your willingness to dive into SK25152 (&lt;A href="https://support.checkpoint.com/results/sk/sk25152" target="_blank" rel="noopener noreferrer"&gt;https://support.checkpoint.com/results/sk/sk25152&lt;/A&gt;) with us was incredibly valuable. I really appreciated how you broke down ISPR’s behavior—highlighting that it should handle failover fine with proper routing (outside of VPN tunnels)&lt;/P&gt;
&lt;DIV&gt;On a related note, I came across a limitation I thought worth mentioning: per SK32073 (&lt;A href="https://support.checkpoint.com/results/sk/sk32073" target="_blank" rel="noopener noreferrer"&gt;Configuring Cluster Addresses on Different Subnets&lt;/A&gt;), &lt;STRONG&gt;ISP Redundancy won’t failover in ClusterXL if the cluster members’ physical interfaces and the VIP are on different subnets&lt;/STRONG&gt;. It’s noted as unsupported and “by design,” which surprised me a bit. (&lt;STRONG&gt;sk66521&lt;/STRONG&gt;)&lt;/DIV&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25509"&gt;@Chinmaya_Naik&lt;/a&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Thu, 06 Mar 2025 10:53:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/243156#M47229</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2025-03-06T10:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point ISP Redundancy - Dynamic Objects (Something Interesting Network)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/243165#M47232</link>
      <description>&lt;P&gt;Glad we can help mate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 06 Mar 2025 12:48:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-ISP-Redundancy-Dynamic-Objects-Something-Interesting/m-p/243165#M47232</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-06T12:48:35Z</dc:date>
    </item>
  </channel>
</rss>

