- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi:
I have questions about ISP redundancy (I am working with R81.20)
I will describe a basic scenario
One Gw with
LAN interafce 192.168.1.1 (LAN is 192.168.1.0)
ISP1 Interface (1.1.1.1, ISP Gw 1.1.1.2)
ISP2 Interface (2.2.2.1 ISP Gw 2.2.2.2)
1) When configuring ISP Reduandancy should I configure 2 default routes in GAIA? or is it configured automaticaly by ISP Redundancy?
2) If you configure a NAT Hide (behind the Gateway) I guess the traffic is NATed with the IP of the ISP the traffic is going out. Is that right?
3) What happens If I NAT inside network with ISP1 IP (1.1.1.1). It may happen that with ISP reduandancy the outgoing traffic is getting out by ISP2. Will the gateway NAT the traffic (going out by ISP2) with ISP1 IP ?
Thanks for your help,
Pablo
1) When configuring ISP Reduandancy should I configure 2 default routes in GAIA? or is it configured automaticaly by ISP Redundancy?
I would configure that in case of main link failure.
2) If you configure a NAT Hide (behind the Gateway) I guess the traffic is NATed with the IP of the ISP the traffic is going out. Is that right?
yes
3) What happens If I NAT inside network with ISP1 IP (1.1.1.1). It may happen that with ISP reduandancy the outgoing traffic is getting out by ISP2. Will the gateway NAT the traffic (going out by ISP2) with ISP1 IP ?
i believe so
Andy
You are wrong - 1.) When an ISP link state changes, the $FWDIR/bin/cpisp_update script runs on the Security Gateway. This script changes the default route of the Security Gateway.
For 2.) see https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityGateway_Guide/Conten...
Also answer to 3.) is false ! After default route is changed the traffic will go out with ISP2 IP.
Not based on my experience with the customers. I had 3 customers experience the issue where if you have ONLY 1 default gateway, if main link goes down, bunch of stuff wont work. You are welcome to test it in the lab and Im positive you would see exact same results.
Andy
Hope this helps.
See https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityGateway_Guide/Conten... for configuration steps ! When an ISP link state changes, the $FWDIR/bin/cpisp_update script runs on the Security Gateway: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityGateway_Guide/Conten...
sk32225 - Configuring ISP Redundancy so that certain traffic uses specific ISP Link
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 14 | |
| 10 | |
| 9 | |
| 7 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY