<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PBRs and ISP redundancy on SMB appliances in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PBRs-and-ISP-redundancy-on-SMB-appliances/m-p/30116#M1236</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&amp;nbsp;After I unchecked the box "Route traffic through this connection by default" the issue seems to be resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Mar 2018 14:12:02 GMT</pubDate>
    <dc:creator>Pedro_Espindola</dc:creator>
    <dc:date>2018-03-09T14:12:02Z</dc:date>
    <item>
      <title>PBRs and ISP redundancy on SMB appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PBRs-and-ISP-redundancy-on-SMB-appliances/m-p/30111#M1231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a centrally managed 1470 appliance with 2 internet connections in High Availatbility:&lt;/P&gt;&lt;P&gt;1. A adsl link connected to DMZ port and ISP redundancy priority 1&lt;/P&gt;&lt;P&gt;2. A dedicated link connected to WAN port and ISP redundancy priority 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Link 1 is fast and great for users, but has upload limit and is unreliable for publications. So I tried to configure a PBR for&amp;nbsp;the&amp;nbsp;dmz network&amp;nbsp;to use link 2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dst:Any&amp;nbsp; src:172.16.30.0/24&amp;nbsp;&amp;nbsp;port:Any&amp;nbsp; next-hop:Link2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also configured automatic static NAT in the corresponding object&amp;nbsp;in SmartConsole.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is that when the server tries to reach the internet for updates and other checks it will use the correct link for a while and then start to fail. When this happens, fw monitor shows this:&lt;/P&gt;&lt;P&gt;o:WAN&lt;/P&gt;&lt;P&gt;O:DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Access from the internet to the server continues to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Restarting the internet connection solves the problem for a few hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried using the external network gateway:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;dst:Any&amp;nbsp; src:1&lt;SPAN&gt;72.16.30&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;SPAN&gt;0&lt;/SPAN&gt;&lt;SPAN&gt;/24&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;port:Any&amp;nbsp; next-hop:&amp;lt;external-gateway&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I doing wrong?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Feb 2018 20:15:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PBRs-and-ISP-redundancy-on-SMB-appliances/m-p/30111#M1231</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-02-15T20:15:57Z</dc:date>
    </item>
    <item>
      <title>Re: PBRs and ISP redundancy on SMB appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PBRs-and-ISP-redundancy-on-SMB-appliances/m-p/30112#M1232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;At least on regular appliances, ISP Redundancy and PBR are mutually exclusive.&lt;/P&gt;&lt;P&gt;That may be the case here... have you opened a case with TAC?&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://www.checkpoint.com/support-services/contact-support/index.html" title="http://www.checkpoint.com/support-services/contact-support/index.html"&gt;Contact Support | Check Point Software&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Feb 2018 21:27:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PBRs-and-ISP-redundancy-on-SMB-appliances/m-p/30112#M1232</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-16T21:27:12Z</dc:date>
    </item>
    <item>
      <title>Re: PBRs and ISP redundancy on SMB appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PBRs-and-ISP-redundancy-on-SMB-appliances/m-p/30113#M1233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see. But then why give us this option?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63223_PBR_Link.PNG" style="width: 620px; height: 272px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will open a service request, but I wanted to open this discussion about the differences between SMB and regular appliances and the usage of these features.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2018 18:30:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PBRs-and-ISP-redundancy-on-SMB-appliances/m-p/30113#M1233</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-02-20T18:30:15Z</dc:date>
    </item>
    <item>
      <title>Re: PBRs and ISP redundancy on SMB appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PBRs-and-ISP-redundancy-on-SMB-appliances/m-p/30114#M1234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is supported according to &lt;EM&gt;Check Point 1100/1200R/1400 Appliances Centrally Managed Administration Guide R77.20.75 p.58:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;ISP Redundancy - supported in IPv4 connections only&lt;/STRONG&gt;&lt;BR /&gt;Multiple Internet connections can be configured in High Availability or Load Sharing modes. When you configure more than one Internet connection, the Device &amp;gt; Internet page lets you toggle between these options. The Advanced setting of each Internet connection lets you configure each connection's priority or weights based on the set mode.&lt;BR /&gt;- Clear the &lt;STRONG&gt;Route traffic through this connection by default&lt;/STRONG&gt; checkbox when you do not want this Internet connection used as a default route for this gateway. The connection is used by the device only if specific, usually service-based, routing rules are defined for it. This is commonly used when you have a connection that is used for dedicated traffic. When you clear this option, this connection does not participate in High Availability or Load Balancing.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And that is not all - i know of customers using this feature successfully, too &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt; !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Feb 2018 09:27:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PBRs-and-ISP-redundancy-on-SMB-appliances/m-p/30114#M1234</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-02-21T09:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: PBRs and ISP redundancy on SMB appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PBRs-and-ISP-redundancy-on-SMB-appliances/m-p/30115#M1235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you get the issue resolved yet?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2018 12:26:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PBRs-and-ISP-redundancy-on-SMB-appliances/m-p/30115#M1235</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-07T12:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: PBRs and ISP redundancy on SMB appliances</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PBRs-and-ISP-redundancy-on-SMB-appliances/m-p/30116#M1236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&amp;nbsp;After I unchecked the box "Route traffic through this connection by default" the issue seems to be resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Mar 2018 14:12:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/PBRs-and-ISP-redundancy-on-SMB-appliances/m-p/30116#M1236</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-03-09T14:12:02Z</dc:date>
    </item>
  </channel>
</rss>

