- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hi Body
I deployed two GW with cluster mode in the aws...the server subnet's default geteway point to active gw eni.
my question is "if the swirtchover happened, how to automatically replace server subnet's nexthop to new active member eni ??? "
i don't find like this script ....
anybody have any idear ?
Can you explain your topology, the layout and what have you done that's not according to the deployment guide.
Hi,
was this ever solved? We have a similar setup and we are struggling to find a way to change routes/interfaces on subnets not created directly by Checkpoint
Hi Kurt
Can you please share your topology and how exactly have you created cluster?
Thanks,
Roman
Hi,
The deployment is based on the fact that the Cluster is installed in its own VPC with no other servers.
so any other Spoke VPCs should be Peered to it with Regular Peering or TGW etc.
The Server VPC routing should take him to the Cluster VPC and there it will have a route directed to the Cluster Active member ENI.
Hi,
This is an existing AWS setup and customer asked us to fit in a Checkpoint Cluster (same AZ). The problem is that they have existing servers directly on the current existing gateway backend interface, as well as a number of Transit Gateways and other pre-existing route tables.
When we deploy a cluster in the existing VPC, the cluster can only change the route tables it created during the deployment. My question is if we can force the new cluster to modify the existing route tables.
I know this is the recommended design from CP, but this is an existing customer topology and they want to deploy CP cluster in the Same VPC.
Thanks,
Kurt
As I remember and tested again , you can associate any Route table to the Cluster's internal Subnet , or other Subnets in That VPC , add routes to the currently ACTIVE member's ENI and that's it.
the failover changes the routes to the ACTIVE member's ENI
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 20 May 2026 @ 11:00 AM (CEST)
The New DDoS Reality: Autonomy, Scale, and the Future of DefenceFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesWed 20 May 2026 @ 11:00 AM (CEST)
The New DDoS Reality: Autonomy, Scale, and the Future of DefenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY