Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jijotms0511
Contributor
Jump to solution

ISP Redundancy with PBR

Hi All,

Can anyone advise if Checkpoint R80.20 can support ISP redundancy with PBR ( PBR presently configured to connect 2 links for wifi users)

Currently ISP redundancy for the main traffic is not configured in the setup and to want to achieve it now? Can anyone advise?

Thanks,

Jijo

 

0 Kudos
2 Solutions

Accepted Solutions
Eduardo_Eiros
Contributor

Hi

I have made some tests with PBR and ISP (HA) redundancy in R80.30. 

PBR still works, meaning traffic is routed by policy rules, but NAT is not performed according "Hide behind gateway" outgoing interface.

NAT is using ISP redundancy primary interface and not real outgoing interface....

Regards

View solution in original post

jijotms0511
Contributor

Thanks for your quick reply.

Understood the same now, if NAT not working then it would be an issue. So just to summarize, then this requirement is not feasible now, what I understand.

 

View solution in original post

0 Kudos
5 Replies
PhoneBoy
Admin
Admin
ISP Redundancy and PBR are mutually exclusive features.
However, you can achieve some level of ISP Redundancy with PBR functionality starting in R80.30.
Specifically, you can create rules in terms of the default route.
jijotms0511
Contributor

Hi Thanks for your reply. Just to make my question more clear, explaining the scenario here.

> Primary link at site , terminating via switches at one of the interface in checkpoint.Main traffic at the site is going via this link.

> Two other links configured via PBR for 2 different wireless connections at site ( due to a specific requirement)

> Noted the point that from R80.30, we could do some level of ISP redundancy in Checkpoint, but my question is in this scenario with total 3 links in total ( One main primary and other 2 PBR), can we configure a redundancy for the primary link for main traffic using the ISP redundancy feature in Checkpoint?

Thanks,

Jijo 

 

0 Kudos
Eduardo_Eiros
Contributor

Hi

I have made some tests with PBR and ISP (HA) redundancy in R80.30. 

PBR still works, meaning traffic is routed by policy rules, but NAT is not performed according "Hide behind gateway" outgoing interface.

NAT is using ISP redundancy primary interface and not real outgoing interface....

Regards

jijotms0511
Contributor

Thanks for your quick reply.

Understood the same now, if NAT not working then it would be an issue. So just to summarize, then this requirement is not feasible now, what I understand.

 

0 Kudos
Gaurav_Pandya
Advisor

Hi,

Please check if below steps resolve the issues

https://community.checkpoint.com/t5/Enterprise-Appliances-and-Gaia/Route-specific-subnet-out-second-...

You can hide behind gateway or IP with ISP2 address.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events