Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Subhojit
Participant
Jump to solution

Auto Hide Nat Redundancy

Hi,

I want to make Nat Rule for redundancy ISP for out going traffic. I have 2 ISP and Objects are Statically nated with their respective IP from ISP.I want configure a fail over nat rule. Is it possible or any other solution will be help full.

* ISPs are terminated in a Cisco Wan Switch and Checkpoint is connected directly with Wan Switch. 

GW version 81.20

 

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

Is it a single ISP or the same ISP with two different NAT numbers?
If they are different ISPs, you should be able to accomplish this via ISP Redundancy.
See: https://support.checkpoint.com/results/sk/sk34812

Otherwise, you should use a Dynamic Object in your NAT rule instead (which is what ISP Redundancy ultimately does).
You'll need to write a script to update the contents of this Dynamic Object using the dynamic_objects CLI command on each gateway that uses this object.
However, this gives you flexibility as to how and when to "fail over" the NAT.

View solution in original post

(1)
8 Replies
PhoneBoy
Admin
Admin

Is it a single ISP or the same ISP with two different NAT numbers?
If they are different ISPs, you should be able to accomplish this via ISP Redundancy.
See: https://support.checkpoint.com/results/sk/sk34812

Otherwise, you should use a Dynamic Object in your NAT rule instead (which is what ISP Redundancy ultimately does).
You'll need to write a script to update the contents of this Dynamic Object using the dynamic_objects CLI command on each gateway that uses this object.
However, this gives you flexibility as to how and when to "fail over" the NAT.

(1)
Subhojit
Participant

Thank you..

 

0 Kudos
Subhojit
Participant

If i configure two IP from different ISPs in a sigle dynamic object.Does NAT will failover to another IP automatically if one ISP fail ? 

0 Kudos
PhoneBoy
Admin
Admin

Configuring more than one IP in a Dynamic Object used in this manner won't fail over.
The script you write will determine the failover conditions and what IP is used in what case.

0 Kudos
the_rock
Legend
Legend

When you say make NAT rules for ISP redundancy, you mean create different nat rules based on what subnets would go out of which ISP link?

Or did I misunderstand that totally?

Andy

0 Kudos
PhoneBoy
Admin
Admin

In this case, you don't need two rules, you only need one...in terms of the Dynamic Object you've created.
The Dynamic Object will determine what the IP will ultimately be translated to.

(1)
the_rock
Legend
Legend

Never knew that was possible...would you mind attach a screenshot of what nat rule would look like in case like that?

Cheers,

Andy

0 Kudos
PhoneBoy
Admin
Admin

The "translated source" would contain the Dynamic Object you created.
It's otherwise like any other NAT rule. 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events