<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dual ISP and SIC management in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/116539#M21678</link>
    <description>&lt;P&gt;I would change the Main IP of the cluster in this case and push policy.&lt;BR /&gt;Assuming the SMS IP doesn't change, that should be all that is required.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Apr 2021 15:19:11 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-04-21T15:19:11Z</dc:date>
    <item>
      <title>Dual ISP and SIC management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/116378#M21659</link>
      <description>&lt;P&gt;Hello mates,&lt;/P&gt;&lt;P&gt;I need your advice. The customer has 3600HA which are managed over the Internet via public IP. So SIC and policy install is going from SMS to cluster via External Public IP of the cluster.&lt;/P&gt;&lt;P&gt;Now the fun part. They have two ISP, with two separate IP pools. Is there any way how to configure management SIC or the object of GW to use any HA for management? I know what happens if ISP A fail, is there way to transfer SIC and policy install to ISP B?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When ISP A fail:&lt;/P&gt;&lt;P&gt;Doing some manual dNAT for GW IP at SMS side? Change traffic to ISP B?&lt;/P&gt;&lt;P&gt;Change IP of cluster in SmartConsole and install?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Apr 2021 07:27:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/116378#M21659</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2021-04-20T07:27:42Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP and SIC management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/116454#M21669</link>
      <description>&lt;P&gt;What is doing the ISP Redundancy/NAT in this case: a Check Point gateway or something else?&lt;BR /&gt;Either way, this SK is probably relevant:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100583&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100583&amp;amp;partition=Advanced&amp;amp;product=Quantum&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;To be clear, SIC is based on certificates, so doesn’t care so much about the IP used.&lt;BR /&gt;However, the IP the gateway connects to for logging and the IP allowed via implied rules is definitely relevant.&lt;/P&gt;
&lt;P&gt;I suspect this will require modifying the masters file to achieve (mentioned in the above SK), though I’m not 100% sure you can specify two IPs for management.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Apr 2021 21:25:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/116454#M21669</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-20T21:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP and SIC management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/116513#M21675</link>
      <description>&lt;P&gt;Currently, there is not any NAT in place, SMS has public IP and GW Cluster has two external eths with two public IPs from both ISP. ISP loadbalance is configured on CP Cluster. Cluster has main IP from ISP A, so policy install and SIC communication is realized to ISP A public IPs.&amp;nbsp;The question is what happens if ISP A fail? How to install policy via ISP B public IP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My assumption which might work when ISP - A fail:&lt;/P&gt;&lt;P&gt;Doing some temporal manual dNAT (x.x.x.x - ISP A to y.y.y.y - ISP B) for connection from SMS to GW&lt;/P&gt;&lt;P&gt;or Change IP of cluster to public IP from ISP B in SmartConsole and try install policy?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 09:55:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/116513#M21675</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2021-04-21T09:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP and SIC management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/116539#M21678</link>
      <description>&lt;P&gt;I would change the Main IP of the cluster in this case and push policy.&lt;BR /&gt;Assuming the SMS IP doesn't change, that should be all that is required.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Apr 2021 15:19:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/116539#M21678</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-21T15:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP and SIC management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/117127#M21799</link>
      <description>&lt;P&gt;I can confirm that its working, just change IP of cluster and its members and you are good go, then policy install. Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Apr 2021 08:07:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/117127#M21799</guid>
      <dc:creator>Martin_Raska</dc:creator>
      <dc:date>2021-04-28T08:07:01Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP and SIC management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/190324#M31882</link>
      <description>&lt;P&gt;Hi ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once ISP1 goes down, do I alway need to change the main IP of Gateway on the Smartconsole to push the policy or make sure Gateway send the logging? Is there any automatic method for that?&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Ercan&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 14:56:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/190324#M31882</guid>
      <dc:creator>starmen2000</dc:creator>
      <dc:date>2023-08-23T14:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP and SIC management</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/190372#M31897</link>
      <description>&lt;P&gt;Unfortunately, not at this time.&lt;/P&gt;
&lt;P&gt;Note that when the primary ISP goes down, the gateway should store logs locally until the primary ISP comes back up and can re-establish a logging connection.&lt;BR /&gt;Which means the logs won't actually be lost, they will just not be available while ISP2 is the active one.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Aug 2023 19:49:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dual-ISP-and-SIC-management/m-p/190372#M31897</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-23T19:49:31Z</dc:date>
    </item>
  </channel>
</rss>

