<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Policy based routing in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Policy-based-routing/m-p/281696#M46804</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I’d like to ask for some advice regarding Policy-Based Routing (PBR), specifically whether using PBR can consume a significant amount of RAM and CPU on a Check Point firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have a ClusterXL setup (no VSX and no Multi-Domain Management), and we are going to have 2 different public subnets from the same ISP.&lt;/P&gt;&lt;P&gt;I have thought of 2 solutions on how to implement a setup where the 2 public subnets&amp;nbsp;can be used simultaneously.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Use the normal default route for all traffic and PBR for the second public subnet&lt;BR /&gt;&lt;SPAN&gt;The first public subnet would use the normal Internet routing configuration. For traffic originating from the second public subnet, or from specific private subnets, PBR would be used to route the traffic appropriately.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2- Use only one default route towards the internet and configure the&amp;nbsp;second public subnet on a physical interface that's NOT facing the internet. I'll ask the ISP to configure a static route for the&amp;nbsp;second public subnet pointing at link we already have with the first subnet. I have only one concern that is NATing for the second subnet, I think it should work with no problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which setup you guys think is the best to be used in this case? and do you think NATing will work if I implement the second solution?&lt;/P&gt;</description>
    <pubDate>Mon, 31 Aug 2026 19:49:11 GMT</pubDate>
    <dc:creator>az26</dc:creator>
    <dc:date>2026-08-31T19:49:11Z</dc:date>
    <item>
      <title>Policy based routing</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Policy-based-routing/m-p/281696#M46804</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I’d like to ask for some advice regarding Policy-Based Routing (PBR), specifically whether using PBR can consume a significant amount of RAM and CPU on a Check Point firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I have a ClusterXL setup (no VSX and no Multi-Domain Management), and we are going to have 2 different public subnets from the same ISP.&lt;/P&gt;&lt;P&gt;I have thought of 2 solutions on how to implement a setup where the 2 public subnets&amp;nbsp;can be used simultaneously.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Use the normal default route for all traffic and PBR for the second public subnet&lt;BR /&gt;&lt;SPAN&gt;The first public subnet would use the normal Internet routing configuration. For traffic originating from the second public subnet, or from specific private subnets, PBR would be used to route the traffic appropriately.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2- Use only one default route towards the internet and configure the&amp;nbsp;second public subnet on a physical interface that's NOT facing the internet. I'll ask the ISP to configure a static route for the&amp;nbsp;second public subnet pointing at link we already have with the first subnet. I have only one concern that is NATing for the second subnet, I think it should work with no problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Which setup you guys think is the best to be used in this case? and do you think NATing will work if I implement the second solution?&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2026 19:49:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Policy-based-routing/m-p/281696#M46804</guid>
      <dc:creator>az26</dc:creator>
      <dc:date>2026-08-31T19:49:11Z</dc:date>
    </item>
  </channel>
</rss>

