- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Good morning,
I am currently running Cluster XL with two 9100s with ISP Redundancy - Load Sharing (50/50) and ran into an issue.
Both of my BGP links are showing 'Established' and both links are showing 'OK'. However, I wanted to test ISP Redundancy, so I powered off my standby appliance and unplugged ISP Link A from the Active and I could not resolve DNS. Internet was lost.
From my understanding, when one ISP Link goes down, the other should take over 100%. This obviously did not happen.
Anything in particular I should look into?
Thank you.
Hello
could you provide some diagram about your network configuration? Just to understand your configuration (routing, interfaces, bgp and so on).
When you perform manual failover to backup ISP it works? So active/standby. How did you resolve DNS, from client or fw itself? Did the logging showed it did a failover? (Smartlog / var/log/messages)
No. I took the standby appliance offline, and then on the active appliance, I remove the link for ISP A. Theoretically, ISP B should have taken over, but at that point, we lost internet until I plugged ISP A back in.
To better help you, we need more information, for example, did you cyheck the output of the command cpstat fw when you disconnected the ISP A? Also reports the output of the command now that you have all the ISPs connected.
Instead of disconnecting firewall or ISP, to simply test ISP B, you could try the command
fw isp_link ISP-A down
(Replace ISP-A with the name of the connection as configured in Smartconsole in ISP redundancy section).
Hi,
When all was normal (cluster OK and IPS-A connected) was ISP Load Sharing working?
Did you see traffic leaving the IPS-B interface when all is OK?
Is NAT configured correctly? What do you see in the logs when it comes to outboud NAT?
If you can provide more info, that would be great?
Martijn
Looking into this further, it appears the second link for ISP-B is not active when I run show route all on my active appliance. It has an 'i' next to the route. So, it was never actually load-sharing like it is configured for.
Hi,
Usually when ISPR is not working it is because it is not configured as required.
Check with "cpstat fw" if both link are up. If both are up, check the NAT configuration of the network that should reach internet: it has to be Automatically hidden behind the gateway".
When both link are up, you should see in the logs some session natted behind ISP1 and some behind ISP2.
Rgds,
Hi,
I have confirmed that both links show 'OK' when I run cpstat fw. I will double check NAT configuration.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 75 | |
| 17 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Thu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 10:00 AM (CEST)
Schutz souveräner Workloads: Check Point & die AWS European Sovereign CloudThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY