<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB Gateway with a WAN Connection but 2 Default  Gateways in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/259686#M13338</link>
    <description>&lt;P&gt;You can't monitor an external IP, only an IP on the same subnet as the WAN.&lt;BR /&gt;That usually means the WAN's default route.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Oct 2025 20:30:26 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-10-10T20:30:26Z</dc:date>
    <item>
      <title>SMB Gateway with a WAN Connection but 2 Default  Gateways</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/259601#M13332</link>
      <description>&lt;P&gt;Hi mates,&lt;/P&gt;&lt;P&gt;I recently had a case with one WAN connection and one IP address, but two default gateways for HA on a 1535 gateway.&lt;BR /&gt;I need to configure the gateway so that, if the primary default gateway fails, it automatically sends traffic to the secondary default gateway. This will ensure redundancy for the internet connection.&lt;/P&gt;&lt;P&gt;My problem is that I don't know how to do it.&lt;BR /&gt;First, it is not possible to define two default gateways for a WAN connection.&lt;BR /&gt;2. It is not possible to prevent the gateway from creating the default gateway automatically, even with the "Route traffic through this connection by default" option disabled under ISP redundancy in the advanced tab of the internet connection settings.&lt;BR /&gt;3. It seems that I have to create two default routes, but, as I described in the last point, I cannot create the primary default route because the gateway created it automatically, and it is not editable. Also, the secondary route that I created stays inactive.&lt;BR /&gt;4. According to this scenario, connection monitoring should be deactivated (apparently) and monitoring should be set on the route. However, this is also not possible for the automatically created default route, and the secondary default route that I created returned an error: "Could not set static route: The next-hop IP address of the monitored route must be on the local LAN subnet." For monitoring VPN or GRE tunnels, select them in the virtual tunnel's hop field." It doesn't matter if I set the IP address of the standard gateway of the ISP or any other IP address, such as a Google DNS IP address.&lt;/P&gt;&lt;P&gt;What could be the solution in this case?&lt;/P&gt;&lt;P&gt;Thanks in Advance&lt;BR /&gt;Regards&lt;BR /&gt;Soroosh&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 08:05:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/259601#M13332</guid>
      <dc:creator>Soroosh</dc:creator>
      <dc:date>2025-10-10T08:05:55Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Gateway with a WAN Connection but 2 Default  Gateways</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/259637#M13333</link>
      <description>&lt;P&gt;Could you please share the firmware version/build used and perhaps a diagram including the relevant IP addresses / netmask details?&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 12:04:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/259637#M13333</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-10-10T12:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Gateway with a WAN Connection but 2 Default  Gateways</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/259686#M13338</link>
      <description>&lt;P&gt;You can't monitor an external IP, only an IP on the same subnet as the WAN.&lt;BR /&gt;That usually means the WAN's default route.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 20:30:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/259686#M13338</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-10-10T20:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Gateway with a WAN Connection but 2 Default  Gateways</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/259744#M13339</link>
      <description>&lt;P&gt;I would agree with what Phoneboy had said, but, if you want to be sure, you can double check with TAC.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 12 Oct 2025 22:45:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/259744#M13339</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-12T22:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Gateway with a WAN Connection but 2 Default  Gateways</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/259755#M13340</link>
      <description>&lt;P&gt;Firmware vewrsion is R&lt;SPAN&gt;R81.10.17_996004721&lt;BR /&gt;I have attached the diagram. I'm not sure if I am allowed to expose the IP addresses, so I have replaced the first three octets with x, and yes, it is /24. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 07:50:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/259755#M13340</guid>
      <dc:creator>Soroosh</dc:creator>
      <dc:date>2025-10-13T07:50:23Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Gateway with a WAN Connection but 2 Default  Gateways</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/259757#M13341</link>
      <description>&lt;P&gt;The problem is that it doesn't accept the IP address of the default gateway either. It shows the same error. Also, I cannot modify/delete/deactivate the automatically created default route.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 07:53:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/259757#M13341</guid>
      <dc:creator>Soroosh</dc:creator>
      <dc:date>2025-10-13T07:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Gateway with a WAN Connection but 2 Default  Gateways</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/261577#M13369</link>
      <description>&lt;P&gt;TAC Answer:&lt;BR /&gt;&lt;SPAN&gt;1. System-Defined Routes Are Not Editable&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"You cannot edit, delete, enable, and disable routes created by the operating system for directly attached networks or by dynamic routing protocols."&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A class="" title="Ursprüngliche URL: https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Centrally_Managed/EN/Content/Topics/Configuring-Routing-Table.htm. Klicken oder tippen Sie, wenn Sie diesem Link Vertrauen." href="https://eur04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsc1.checkpoint.com%2Fdocuments%2FSMB_R81.10.X%2FAdminGuides_Centrally_Managed%2FEN%2FContent%2FTopics%2FConfiguring-Routing-Table.htm&amp;amp;data=05%7C02%7Csoroosh.saneinia%40schrittmachergmbh.mail.onmicrosoft.com%7C66d5c589ec1745cbf4c708de17a861d5%7C2202b771f6bb4497987e8333e445e388%7C0%7C0%7C638974209147669497%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=saLQ5SR5H%2BVf0%2Fp6KTYNjyPKCric%2BiBbGCDiD0KWQHw%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Centrally_Managed/EN/Content/Topics/Configuring-Routing-Table.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;2. Default Route Failover Is Tied to Interface Status&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;If the WAN interface goes down, the default route becomes inactive, and traffic is routed according to other active routes.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The system does not support two default gateways for a single WAN interface.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;3. ISP Redundancy Feature&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Designed for multiple WAN interfaces (e.g., WAN1, WAN2), not for two gateways on one interface.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;"Route traffic through this connection by default" only applies to the selected WAN interface.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;4. Static Route Monitoring Limitations&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Monitored static routes require the next-hop to be on a local subnet.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;You cannot use an external IP as the next-hop for route monitoring.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;5. Cluster/HA Solutions&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;True HA with automatic failover between gateways is supported via cluster configuration (ClusterXL or Quantum Spark cluster), but this requires two appliances and typically two WAN interfaces.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Please check admin guide to configure High Availability:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A class="" title="Ursprüngliche URL: https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Configuring-High-Availability.htm. Klicken oder tippen Sie, wenn Sie diesem Link Vertrauen." href="https://eur04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsc1.checkpoint.com%2Fdocuments%2FSMB_R81.10.X%2FAdminGuides_Locally_Managed%2FEN%2FContent%2FTopics%2FConfiguring-High-Availability.htm&amp;amp;data=05%7C02%7Csoroosh.saneinia%40schrittmachergmbh.mail.onmicrosoft.com%7C66d5c589ec1745cbf4c708de17a861d5%7C2202b771f6bb4497987e8333e445e388%7C0%7C0%7C638974209147683683%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=ErkU5Zi2MZxqCx4%2BOc2pCC2GqcEFokUNmI5BjohG1%2BI%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Configuring-High-Availability.htm&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ISP Redundancy:&lt;/SPAN&gt;&lt;BR /&gt;&lt;A class="" title="Ursprüngliche URL: https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Configuring-Internet-Connectivity.htm?Highlight=ISP%20Redundancy. Klicken oder tippen Sie, wenn Sie diesem Link Vertrauen." href="https://eur04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fsc1.checkpoint.com%2Fdocuments%2FSMB_R81.10.X%2FAdminGuides_Locally_Managed%2FEN%2FContent%2FTopics%2FConfiguring-Internet-Connectivity.htm%3FHighlight%3DISP%2520Redundancy&amp;amp;data=05%7C02%7Csoroosh.saneinia%40schrittmachergmbh.mail.onmicrosoft.com%7C66d5c589ec1745cbf4c708de17a861d5%7C2202b771f6bb4497987e8333e445e388%7C0%7C0%7C638974209147697996%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&amp;amp;sdata=%2FrKa2gK%2Fo449og6ILPp6NnnNg4MGvZPtfTCQbz5efMg%3D&amp;amp;reserved=0" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Configuring-Internet-Connectivity.htm?Highlight=ISP%20Redundancy&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;​​​​​​​&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;So, I had to set 2 IPs on the WAN Port, and sat the Primary DG for one and the secondary for another.&lt;BR /&gt;with this method I could find a solution for this case. And it seems it works.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2025 12:00:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Gateway-with-a-WAN-Connection-but-2-Default-Gateways/m-p/261577#M13369</guid>
      <dc:creator>Soroosh</dc:creator>
      <dc:date>2025-10-31T12:00:41Z</dc:date>
    </item>
  </channel>
</rss>

