- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi
I am looking to understand how Checkpoint Cloudguard BGP routing works when ECMP is enabled. I've got 2 equal paths to a destination, and I want to install routes learnt from both paths into the routing table. However, I want to ensure that traffic from the same source IP is always sent to the same path (client persistency).
Is there a way to configure this sort of hashing (source-IP persistency) within ECMP?
Per sk100504:
With two equal cost paths, they both will be installed to the routing table (the FIB). Routing is based on destinations, not sources. You need PBR for source based routing (don’t do PBR; it’s an endless pit of trouble unless you absolutely positively must). Even source NAT doesn’t solve the issue.
If you want to ensure a packet travels via a predetermined path then you don’t have ECMP anymore. You can use BGP path attributes to influence path decisions between ASNs if you need that. Local_Pref, AS_Path, and/or Weight (locally significant to the router only) to exit an AS; MED to enter an AS.
Thanks for your feedback. Unfortunately, BGP Attributes will not solve my problem, as I need traffic to be routed across 2 paths. Adding local pref will only make traffic go via one path. What I need is the ability to load balance based on a source-ip-based algorithm
Per sk100504:
That's a shame but thanks for researching
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY