<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT with two ISP lines in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220896#M36804</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;.&amp;nbsp; This seems interesting but I suspect it isn't what I need.&amp;nbsp; I think my issue relates to getting return/reply traffic back out of the interface it arrived at.&amp;nbsp; My interpretation of that SK is for packets initiated from the LAN outbound.&amp;nbsp; In my case packets are initiated from the Internet inbound, which arrive fine, but the reply traffic leaves from a different interface.&lt;/P&gt;&lt;P&gt;So SYN comes into ISP-A on eth0, but the SYN-ACK leaves via eth1 (the new ISP line, and new Default Gateway).&amp;nbsp; How do I get the SYN-ACK to return via eth0 instead, to avoid asymmetric routing?&lt;/P&gt;&lt;P&gt;I'm assuming that's my issue here because once the default gateway is set to ISP-B, none of the NAT's on ISP-A work any more.&amp;nbsp; If I add a static route to my Internet test machine via ISP-A then I can access everything normally again.&amp;nbsp; So it seems stateful reply traffic is following the routing table and breaking the connections.&amp;nbsp; &amp;nbsp;While ISP-B is default, I simply need a way to still be able to access NAT's on ISP-A.&lt;/P&gt;&lt;P&gt;Maybe if I hide NAT behind the ISP-A interface IP on the way in that would work?&amp;nbsp; It's horribly messy, but worth a try.&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jul 2024 07:31:58 GMT</pubDate>
    <dc:creator>madu1</dc:creator>
    <dc:date>2024-07-16T07:31:58Z</dc:date>
    <item>
      <title>NAT with two ISP lines</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220760#M36780</link>
      <description>&lt;P&gt;I've just added a new/second ISP line to my gateway and made this my primary ISP line.&amp;nbsp; ISP Redundancy is configured.&lt;/P&gt;&lt;P&gt;LAN traffic to the Internet leaves via the default gateway of ISP line 1 - the new line.&amp;nbsp; All good.&lt;/P&gt;&lt;P&gt;I still have a load of servers with static NAT on what is now the secondary ISP line.&amp;nbsp; These no longer work.&amp;nbsp; Tcpdump shows traffic arriving from the Internet via ISP line 2, but return traffic routes out via the default gateway on ISP 1.&amp;nbsp; Asymmetric routing...&lt;/P&gt;&lt;P&gt;How do I get this traffic to return via the interface it arrived on - back via ISP 2?&lt;/P&gt;&lt;P&gt;I've got other gateways with the same dual ISP configuration, and they work fine. Return traffic goes back out via the interface from which it arrived.&amp;nbsp; But not this gateway.&amp;nbsp; Any ideas why not and how to fix it?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 10:35:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220760#M36780</guid>
      <dc:creator>madu1</dc:creator>
      <dc:date>2024-07-15T10:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with two ISP lines</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220772#M36784</link>
      <description>&lt;P&gt;Are all the gateways on a common version &amp;amp; JHF level?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 12:17:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220772#M36784</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-07-15T12:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with two ISP lines</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220773#M36785</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;Yeah, R81.20 Take 26 (cluster).&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 12:20:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220773#M36785</guid>
      <dc:creator>madu1</dc:creator>
      <dc:date>2024-07-15T12:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with two ISP lines</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220778#M36786</link>
      <description>&lt;P&gt;Do you have simple diagram?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 12:48:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220778#M36786</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-15T12:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with two ISP lines</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220854#M36794</link>
      <description>&lt;P&gt;So they're all Check Point gateways and one set of them is having an issue?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 20:38:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220854#M36794</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-15T20:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with two ISP lines</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220857#M36795</link>
      <description>&lt;P&gt;This will give guidance I suspect:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk25152" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk25152&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 20:43:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220857#M36795</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-07-15T20:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with two ISP lines</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220895#M36803</link>
      <description>&lt;P&gt;I think just ignore the line where I said I have other gateways...&amp;nbsp; I was simply saying here to compare to other cases with dual ISP where I can still access the NAT address on the second/standby line with no problem - but it's not working on &lt;EM&gt;this&lt;/EM&gt; particular gateway.&lt;/P&gt;&lt;P&gt;This of this case evolution as:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have a single gateway with a single ISP line.&amp;nbsp; (ISP-A)&lt;/LI&gt;&lt;LI&gt;Static NAT assigned to an internal host - from the ISP-A subnet.&lt;/LI&gt;&lt;LI&gt;Then I add an additional ISP line - ISP-B.&lt;/LI&gt;&lt;LI&gt;I make ISP-B the "primary" Internet circuit and change the Default Gateway on the firewall to use ISP-B.&lt;/LI&gt;&lt;LI&gt;I configure ISP Redundancy in HA mode, with ISP-B at the top of the list.&lt;/LI&gt;&lt;LI&gt;Once I do that, people on the Internet can no longer access the server via the NAT on ISP-A.&amp;nbsp; Tcpdump shows traffic coming in on the ISP-A interface, getting to the internal host, but then returning via ISP-B and the connection doesn't work.&lt;/LI&gt;&lt;LI&gt;SYN in through one interface...&amp;nbsp; SYN-ACK back via a different interface.&amp;nbsp; Asymmetric routing.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So my question was how can I keep things working when it has a static NAT on the &lt;EM&gt;other&lt;/EM&gt; ISP line?&lt;/P&gt;&lt;P&gt;Or in other words - how can I make inbound traffic arriving on the ISP-A interface also return out of the ISP-A interface so I don't get asymmetric routing?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 07:19:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220895#M36803</guid>
      <dc:creator>madu1</dc:creator>
      <dc:date>2024-07-16T07:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with two ISP lines</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220896#M36804</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73547"&gt;@Lesley&lt;/a&gt;.&amp;nbsp; This seems interesting but I suspect it isn't what I need.&amp;nbsp; I think my issue relates to getting return/reply traffic back out of the interface it arrived at.&amp;nbsp; My interpretation of that SK is for packets initiated from the LAN outbound.&amp;nbsp; In my case packets are initiated from the Internet inbound, which arrive fine, but the reply traffic leaves from a different interface.&lt;/P&gt;&lt;P&gt;So SYN comes into ISP-A on eth0, but the SYN-ACK leaves via eth1 (the new ISP line, and new Default Gateway).&amp;nbsp; How do I get the SYN-ACK to return via eth0 instead, to avoid asymmetric routing?&lt;/P&gt;&lt;P&gt;I'm assuming that's my issue here because once the default gateway is set to ISP-B, none of the NAT's on ISP-A work any more.&amp;nbsp; If I add a static route to my Internet test machine via ISP-A then I can access everything normally again.&amp;nbsp; So it seems stateful reply traffic is following the routing table and breaking the connections.&amp;nbsp; &amp;nbsp;While ISP-B is default, I simply need a way to still be able to access NAT's on ISP-A.&lt;/P&gt;&lt;P&gt;Maybe if I hide NAT behind the ISP-A interface IP on the way in that would work?&amp;nbsp; It's horribly messy, but worth a try.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 07:31:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220896#M36804</guid>
      <dc:creator>madu1</dc:creator>
      <dc:date>2024-07-16T07:31:58Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with two ISP lines</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220954#M36813</link>
      <description>&lt;P&gt;Hmmm could it be it is because the setup is in HA mode? Instead of 50/50?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe check this out, many tips there to verify:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk61692" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk61692&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you are running load-sharing:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk34812" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk34812&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hide NAT&amp;nbsp;should be configured. Every connection without Hide Address Translation will not be included in the ISP Redundancy routing and go through the default primary gateway.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 13:02:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/220954#M36813</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-07-16T13:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with two ISP lines</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/222071#M37007</link>
      <description>&lt;P&gt;Did you try to configure a PBR for the internal host natted on isp A?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jul 2024 12:39:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/222071#M37007</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2024-07-28T12:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with two ISP lines</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/223029#M37135</link>
      <description>&lt;P&gt;So the answer turned out to be easy, and was completely my error.&lt;/P&gt;&lt;P&gt;It requires correct ISP Redundancy config.&amp;nbsp; I'd forgotten to put the new ISP line into ISP Redundancy, so the firewall had no route out of that new interface, hence just resorting to the default route out of the wrong interface.&amp;nbsp; Once this was entered everything immediately worked &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 08:36:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/223029#M37135</guid>
      <dc:creator>madu1</dc:creator>
      <dc:date>2024-08-08T08:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: NAT with two ISP lines</title>
      <link>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/223046#M37141</link>
      <description>&lt;P&gt;Good job&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/113035"&gt;@madu1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 11:51:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/NAT-with-two-ISP-lines/m-p/223046#M37141</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-08T11:51:35Z</dc:date>
    </item>
  </channel>
</rss>

