- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello CP Experts -
I have 2 CheckPoints 5100 in HA. Currently firewall fail-over takes place if primary firewall gets down physically. Now I want to setup in a way that if my WAN interface IP on primary firewall gets unreachable it will shift the traffic flow on the secondary firewall, Means my primary firewall need to be up physically but just due to its WAN interface gets unreachable it should make a route of all network traffic to secondary firewall and on Secondary firewall an alternate ISP starts Natting and making the internet reachable.
I hope I cleared my question. Looking forward for positive reply in this regards.
Unless both gateways share the same subnet on all interfaces, have a shared IP, and can reach each other on all interfaces, you won't be able to cluster.
The shared IP would have to be reachable on both ISPs, which is not likely the case.
Also a cluster has to have exact the same policy (including NAT) on all members, which is not what you're asking for.
Bottom line: this won't work as a cluster.
Further, since this thread is in English, I am moving it to the proper space: General Product Topics
Hi, just a quick question, but if you have already an alternate ISP why not connect this to both gateways and have ISP redundancy on both gateways ? So on both gateways (active/passive) both ISP's are connected and in or load sharing mode or in Primary/Backup mode. I think that would make a bit more sense.
From the second edition of my book:
Question: We suffered an upstream network failure that did not occur on the network/VLAN directly adjacent to the firewall. There was not a failover to the standby member (who had a working network path further upstream) because ClusterXL could not detect this indirect upstream network failure. Can we configure ClusterXL to monitor some upstream IP addresses, and cause a failover to occur when they can no longer be reached?
Answer: Yes! See sk35780: How to configure $FWDIR/bin/clusterXL_monitor_ips script to run automatically on Gaia / Sec....
--
Second Edition of my "Max Power" Firewall Book
Now Available at http://www.maxpowerfirewalls.com
Hello everyone thank you for your responses. Further I need to design like this to have both Firewalls in active mode and need to have a failover to the cluster firewall if the WAN link gets unreachable.
You can have both Firewalls in active mode and use two ISPs with ISP redundancy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY