<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB Cluster Route redundancy in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Route-redundancy/m-p/251415#M12822</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;A quick update, just to finish the question.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The issue was not on the Route Map, which are pretty straightforward. The thing is that the OSPF route are appearing as External Type, which have a default Rank of 150, greater than 60 of the static default route. I've changed that advanced parameter to 180 and the OSPF default route is now being used, as it should be.&lt;/P&gt;&lt;P&gt;Thanks a lot for your help!&lt;/P&gt;&lt;P&gt;Have a nice day.&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jun 2025 10:04:23 GMT</pubDate>
    <dc:creator>Oryx</dc:creator>
    <dc:date>2025-06-17T10:04:23Z</dc:date>
    <item>
      <title>SMB Cluster Route redundancy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Route-redundancy/m-p/251214#M12807</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have and end customer with multiple remote sites with 1590/1570 Clusters that connect to the resources on the DC and the Internet over a 9300 Cluster. They are running OSPF, so the remote sites can advertise their local networks and the Main DC advertise the default route.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now they are deploying a new Backup DC and want to have a redundant link over that Backup DC. So far, so good for me. I'm sharing a little diagram.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled Diagram.drawio.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30753i53D012BFC6D1D268/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Untitled Diagram.drawio.png" alt="Untitled Diagram.drawio.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;My issue is that the end customer has configured the port WAN as Internet connection, which forces to configure a default gateway, defining a default route on the Routing Table.&lt;/P&gt;&lt;P&gt;So, how can I announce a default over OSPF from the BACKUP DC and make sure that the traffic comming from the Remote Site uses that second link, if I have a default static route announced through the WAN port? Can the Monitoring feature (disabled at this moment) be helpful for this? Or my only option is to reconfigure the connection on the WAN Port as normal, without being an Internet connection type?&lt;/P&gt;&lt;P&gt;Many thanks in advance.&lt;/P&gt;&lt;P&gt;Kind regards.&amp;nbsp;&lt;/P&gt;&lt;P&gt;P.S.: All of the clusters are managed on a On Prem Security Management.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 11:08:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Route-redundancy/m-p/251214#M12807</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2025-06-13T11:08:37Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster Route redundancy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Route-redundancy/m-p/251217#M12808</link>
      <description>&lt;P&gt;If needed you should be able to manipulate this Advanced setting/value:&lt;/P&gt;
&lt;P&gt;OS advanced settings - Default route rank&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_20250613-193247~2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30755i4226785F6FD0B111/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_20250613-193247~2.png" alt="Screenshot_20250613-193247~2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Routing protocol ranks should be aligned with normal GAiA in theory:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_Advanced_Routing_AdminGuide/Topics-GARG/Routing-Options-Protocol-Rank.htm#:~:text=The%20protocol%20rank%20is%20the,routes%20to%20the%20same%20destination" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_Advanced_Routing_AdminGuide/Topics-GARG/Routing-Options-Protocol-Rank.htm#:~:text=The%20protocol%20rank%20is%20the,routes%20to%20the%20same%20destination&lt;/A&gt;.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 13:19:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Route-redundancy/m-p/251217#M12808</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-06-13T13:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster Route redundancy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Route-redundancy/m-p/251227#M12811</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks. I was not aware of this option. However, if everything goes normally, the OSPF rank is 10, which will prevail over the static route rank 60. So, in theory, the OSPF route will have precedence over the static one, right?&lt;/P&gt;&lt;P&gt;Kind regards.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 14:05:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Route-redundancy/m-p/251227#M12811</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2025-06-13T14:05:54Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster Route redundancy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Route-redundancy/m-p/251229#M12812</link>
      <description>&lt;P&gt;If it's a normal OSPF route that's correct if it shows as the other type you may need the above option but you can evaluate the rank at the time and adjust accordingly.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 14:35:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Route-redundancy/m-p/251229#M12812</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-06-13T14:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster Route redundancy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Route-redundancy/m-p/251231#M12813</link>
      <description>&lt;P&gt;The OSPF route is showing as "inactive", but I think it's because of the route-map applied. Anyway, I will need to try and check.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jun 2025 14:43:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Route-redundancy/m-p/251231#M12813</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2025-06-13T14:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Cluster Route redundancy</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Route-redundancy/m-p/251415#M12822</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;A quick update, just to finish the question.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The issue was not on the Route Map, which are pretty straightforward. The thing is that the OSPF route are appearing as External Type, which have a default Rank of 150, greater than 60 of the static default route. I've changed that advanced parameter to 180 and the OSPF default route is now being used, as it should be.&lt;/P&gt;&lt;P&gt;Thanks a lot for your help!&lt;/P&gt;&lt;P&gt;Have a nice day.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 10:04:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Cluster-Route-redundancy/m-p/251415#M12822</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2025-06-17T10:04:23Z</dc:date>
    </item>
  </channel>
</rss>

