<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy Based Routing for only internet traffic in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/88936#M6841</link>
    <description>From R80.30, you can create PBR rules where the default route is the destination.&lt;BR /&gt;Meaning, you only need one PBR route for that VLAN to be routed out a different Internet connection.&lt;BR /&gt;&lt;BR /&gt;In earlier releases, you can achieve something similar by creating a series of more specific PBR routes.</description>
    <pubDate>Wed, 17 Jun 2020 17:28:23 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-06-17T17:28:23Z</dc:date>
    <item>
      <title>Policy Based Routing for only internet traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/88559#M6820</link>
      <description>&lt;P&gt;Team,&lt;/P&gt;&lt;P&gt;Is it possible to configure for internet traffic or IP range in destination, One of my Customer wants to route for particular VLAN&amp;nbsp; traffic should use third internet link but customer environment have 30 routing entry for their enterprise network so in this case, I need to configure 30 PBR entry for the internal networks?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jun 2020 07:15:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/88559#M6820</guid>
      <dc:creator>Mithu</dc:creator>
      <dc:date>2020-06-15T07:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing for only internet traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/88936#M6841</link>
      <description>From R80.30, you can create PBR rules where the default route is the destination.&lt;BR /&gt;Meaning, you only need one PBR route for that VLAN to be routed out a different Internet connection.&lt;BR /&gt;&lt;BR /&gt;In earlier releases, you can achieve something similar by creating a series of more specific PBR routes.</description>
      <pubDate>Wed, 17 Jun 2020 17:28:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/88936#M6841</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-17T17:28:23Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing for only internet traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/90485#M6922</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; Agreed that solution provides for internet traffic through another ISP, when I put similar PBR for particular VLAN all the traffic including internal subnet also forwarded to ISP link, herewith I have attached simplified network overview.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scenarios:&lt;/P&gt;&lt;P&gt;1. ISP 1 - Primary INT&lt;/P&gt;&lt;P&gt;2.ISP 2 - Specific user&amp;nbsp;internet access (managers)&lt;/P&gt;&lt;P&gt;3.ISP 3 -&amp;nbsp;&amp;nbsp;Specific server segment internet access&lt;/P&gt;&lt;P&gt;Near Future expansion&lt;/P&gt;&lt;P&gt;4. ISP-4 SIP link for softPBX server&lt;/P&gt;&lt;P&gt;5.ISP-5 secondary internet going to participate ISP redundancy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe PBR table would be enormous also very hard to manage, Please suggest best practice to maintain less configuration to fulfill the requirement (please consider MPLS network will be used by users/servers to access some service from corporate network)&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2020 13:40:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/90485#M6922</guid>
      <dc:creator>Mithu</dc:creator>
      <dc:date>2020-07-03T13:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing for only internet traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/90526#M6930</link>
      <description>What precise release are you running?&lt;BR /&gt;If it's less than R80.30, I highly recommend upgrading for reasons beyond just this issue.&lt;BR /&gt;If you don't want to upgrade, you'd basically have to create a number of routes that exclude your internal address space.&lt;BR /&gt;It's difficult to tell from the very generic network diagram you provided what the scope of this challenge would be.&lt;BR /&gt;If the environment changes regularly, then even once you've configured it, maintaining it will be an ongoing challenge.&lt;BR /&gt;In which case, you'll save yourself a lot of work by upgrading.</description>
      <pubDate>Sat, 04 Jul 2020 07:34:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/90526#M6930</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-04T07:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing for only internet traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/90528#M6931</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; I have upgraded to R80.30 OS, So what is the best way to configure PBR. The best practice??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jul 2020 07:40:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/90528#M6931</guid>
      <dc:creator>Mithu</dc:creator>
      <dc:date>2020-07-04T07:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing for only internet traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/90529#M6932</link>
      <description>The way routing works in general is more specific routes will be preferred over routes that are more general (like the default route).&lt;BR /&gt;So if you have routes for those other networks on your gateway, then you should just need a single PBR route with source that VLAN, destination default route.&lt;BR /&gt;It's possible that you might also need to create more specific PBR routes for those other networks as well as I'm not entirely clear on how "regular" routes and "PBR" routes interact in this case.</description>
      <pubDate>Sat, 04 Jul 2020 08:04:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/90529#M6932</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-07-04T08:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing for only internet traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/90532#M6934</link>
      <description>&lt;P&gt;I understood, but the default route includes all the addresses(any), it would be much easier if there is an option in PBR for internet routes (Public IP addresses only). Please consider this in future releases.&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jul 2020 08:57:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/90532#M6934</guid>
      <dc:creator>Mithu</dc:creator>
      <dc:date>2020-07-04T08:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing for only internet traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/158759#M27711</link>
      <description>&lt;P&gt;Hi Mithu - Would like to know what you did to resolve the internet only issue, we are facing the same challenges.&lt;BR /&gt;Thanks,&lt;BR /&gt;Tim&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 16:07:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/158759#M27711</guid>
      <dc:creator>timothyjwitt</dc:creator>
      <dc:date>2022-10-04T16:07:07Z</dc:date>
    </item>
    <item>
      <title>Re: Policy Based Routing for only internet traffic</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/158771#M27716</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;You have to create another PBR table which includes all your local network and static routes and apply that table before the 'internet only' pbr rule. It is very well explained in this post&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Route-specific-subnet-out-second-ISP-interface/m-p/32730" target="_blank"&gt;Solved: Route specific subnet out second ISP interface - Check Point CheckMates&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 17:08:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Policy-Based-Routing-for-only-internet-traffic/m-p/158771#M27716</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2022-10-04T17:08:05Z</dc:date>
    </item>
  </channel>
</rss>

