<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISP Redundancy and dynamic routing in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-and-dynamic-routing/m-p/247782#M48416</link>
    <description>&lt;P&gt;I could have sworn there was a different sk about this, but they may had integrated into one you mentioned. I know we configured BGP for a client while ago and also enabled ISPR on 6400 model and works fine since 2021, no issues. Its possible was supported back then : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 30 Apr 2025 12:11:57 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-04-30T12:11:57Z</dc:date>
    <item>
      <title>ISP Redundancy and dynamic routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-and-dynamic-routing/m-p/247779#M48415</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I'm evaluating my current setup for my outgoing traffic (aka internal users accessing the internet).&lt;/P&gt;&lt;P&gt;I noticed that there is a feature called ISP Redundancy, which would allow me to have two uplinks. But i noticed that various documentations say, that i can't use the redundancy when i have dynamic routing protocols in use.&lt;/P&gt;&lt;P&gt;But if i don't use OSPF to learn the default route, would these feature still clash?&lt;BR /&gt;For example, if i either only announce routes (eg a default route into the internal network) or learn smaller routes from other devices (eg 192.168.0.0/24 from some router).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;These are the mentioned KBs:&lt;/P&gt;&lt;P&gt;R81.20 ClusterXL Administration Guide&lt;/P&gt;&lt;P&gt;Important - ISP Redundancy is not supported if Dynamic Routing is configured (Known Limitation PMTR-68991).&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ClusterXL_AdminGuide/Content/Topics-CXLG/ISP-Redundancy-on-Cluster.htm?Highlight=ISP" target="_self"&gt;R81.20 ClusterXL AdminGuide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Known Limitations for Scalable Platforms R80.20SP - R81.20 (Maestro Appliances and Chassis)&lt;/P&gt;&lt;P&gt;PMTR-68991 - Scalable Platforms do not support ISP Redundancy if Dynamic Routing is configured (because the ISP Redundancy feature must create a static default route that overrides the default route created by dynamic routing)&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk148074" target="_self"&gt;sk148074&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 11:53:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-and-dynamic-routing/m-p/247779#M48415</guid>
      <dc:creator>SomAustrianCity</dc:creator>
      <dc:date>2025-04-30T11:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy and dynamic routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-and-dynamic-routing/m-p/247782#M48416</link>
      <description>&lt;P&gt;I could have sworn there was a different sk about this, but they may had integrated into one you mentioned. I know we configured BGP for a client while ago and also enabled ISPR on 6400 model and works fine since 2021, no issues. Its possible was supported back then : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 12:11:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-and-dynamic-routing/m-p/247782#M48416</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-30T12:11:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Redundancy and dynamic routing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-and-dynamic-routing/m-p/247808#M48420</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Known Limitation PMTR-68991 not present here for R81.20&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk174965" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk174965&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;It does show for R81.10&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk166717" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk166717&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The R81.20 guide still shows the limitation in the documentation:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityGateway_Guide/Content/Topics-FWG/ISP-Redundancy-on-Security-Gateway.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityGateway_Guide/Content/Topics-FWG/ISP-Redundancy-on-Security-Gateway.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So Check Point either has to change the know limitations page for R81.10 and R81.20 or change the admin guides.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry not able to help further. This needs to be an official statement.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Apr 2025 15:00:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Redundancy-and-dynamic-routing/m-p/247808#M48420</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-04-30T15:00:55Z</dc:date>
    </item>
  </channel>
</rss>

