<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: can i bypass PBR for internal networks in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/can-i-bypass-PBR-for-internal-networks/m-p/135399#M24232</link>
    <description>&lt;P&gt;As an idea....&lt;/P&gt;
&lt;P&gt;Try to define your PBR rules not only with filters for source use ports too if possible.&lt;/P&gt;
&lt;P&gt;Another way ... create PBR rules for your internal networks as destination and use more then one gateway as next hops. Then you can define priorities for this PBR routes and you can use "monitored IPs" to check the availability of links for these routes. With this you get something something like a "dynamic" routing for the PBR rules.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Dec 2021 13:11:53 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2021-12-02T13:11:53Z</dc:date>
    <item>
      <title>can i bypass PBR for internal networks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/can-i-bypass-PBR-for-internal-networks/m-p/135384#M24226</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;i'm pretty sure it's not possible, but i'll ask anyway&lt;/P&gt;&lt;P&gt;here is the scenario.&lt;/P&gt;&lt;P&gt;we have an sdwan in dmz behind the FW.&lt;/P&gt;&lt;P&gt;the fw have ospf vs the sdwan so it gets updated dynamically on the availability of remote networks, and also have bgp against other fw's with bgp as a backup path.&lt;/P&gt;&lt;P&gt;now i want to create a pbr rule that if users goes to default route (intetnet surf) then the next hop will be the sdwan, so internet traffic will be controlled by the sdwan only.&lt;/P&gt;&lt;P&gt;the thing is if i do that, than routes to internal networks will not go to dynamic routes from that source lan, they will stuck at pbr where they are the mached.&lt;/P&gt;&lt;P&gt;is there anyway to tell the pbr that if the dst is internal network than bypass to kernel routes, and if it isn't then take the default route from pbr.&lt;/P&gt;&lt;P&gt;or any other way.&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 08:54:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/can-i-bypass-PBR-for-internal-networks/m-p/135384#M24226</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2021-12-02T08:54:03Z</dc:date>
    </item>
    <item>
      <title>Re: can i bypass PBR for internal networks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/can-i-bypass-PBR-for-internal-networks/m-p/135390#M24228</link>
      <description>&lt;P&gt;PBR rules are checked before all other routing services (static or dynamic routes). Only if your PBR filter does not match the packets are forwarded to the other routing daemons for processing.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 09:44:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/can-i-bypass-PBR-for-internal-networks/m-p/135390#M24228</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-12-02T09:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: can i bypass PBR for internal networks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/can-i-bypass-PBR-for-internal-networks/m-p/135393#M24229</link>
      <description>&lt;P&gt;i know this how it works formally. this is why i asked if there is a way to make a bypass somehow in my scenario. i guess there isn't.&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 11:22:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/can-i-bypass-PBR-for-internal-networks/m-p/135393#M24229</guid>
      <dc:creator>Amir_Arama</dc:creator>
      <dc:date>2021-12-02T11:22:45Z</dc:date>
    </item>
    <item>
      <title>Re: can i bypass PBR for internal networks</title>
      <link>https://community.checkpoint.com/t5/General-Topics/can-i-bypass-PBR-for-internal-networks/m-p/135399#M24232</link>
      <description>&lt;P&gt;As an idea....&lt;/P&gt;
&lt;P&gt;Try to define your PBR rules not only with filters for source use ports too if possible.&lt;/P&gt;
&lt;P&gt;Another way ... create PBR rules for your internal networks as destination and use more then one gateway as next hops. Then you can define priorities for this PBR routes and you can use "monitored IPs" to check the availability of links for these routes. With this you get something something like a "dynamic" routing for the PBR rules.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 13:11:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/can-i-bypass-PBR-for-internal-networks/m-p/135399#M24232</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-12-02T13:11:53Z</dc:date>
    </item>
  </channel>
</rss>

