- Products
- Learn
- Local User Groups
- Partners
- More
Stop Babysitting Rules.
Go Agentic
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
We have an HA firewall pair, and 2 ISP links. We want to utilize Policy based routing AND have traffic fail-over completely to either ISP1 or ISP2 if the circuit goes down.
Example:
- Net_10.1.1.0/24 goes through the Checkpoints and out ISP1
- Net_192.168.1.0/24 goes through the Checkpoints and out ISP2
If ISP1 goes down, then both Net_10.1.1.0/24 and Net_192.168.1.0/24 will be sent out ISP2, and vice versa.
Is this possible with PBR?
Thanks
That should be possible with PBR, yes.
Hey Jeff,
Check out below post I made before holidays.
https://community.checkpoint.com/t5/Security-Gateways/ISP-redundancy-PBR-sd-wan-question/m-p/265222
That should be possible with PBR, yes.
Hey Jeff,
Check out below post I made before holidays.
https://community.checkpoint.com/t5/Security-Gateways/ISP-redundancy-PBR-sd-wan-question/m-p/265222
did i study how to apply nat? in case of zone+r82 pay attention and take a look here https://support.checkpoint.com/results/sk/sk184176
Hey Jeff,
Hope link I shared helped?
Happy weekend!
Yep. Helped clarify things. Appreciate it.
For you, no charge...EXCEPT iphone charge. Thats my CORNY joke Im sure everyone is sick of lol
Anyway, yea, you can definitely open TAC case, though Im positive they will tell you the same thing.
For reference:
https://support.checkpoint.com/results/sk/sk167135
Be free to message me directly any time, I have a very good lab set up, so most things can be tested.
Yes, PBR should allow that
The catch is...would allow that, but PBR ONLY...NO ISPR involved : - )
Together, wont work.
Thanks all for the responses. As I am getting mixed responses perhaps a TAC case is best.
Regards,
Their is conceptual & feature naming...
ISP redundancy doesn't necessarily mean you are using the Check Point feature by the same name where PBR is a limitation.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 18 | |
| 9 | |
| 9 | |
| 8 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY