cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post

ISP Redundancy with PBR

Jump to solution

Hi All,

Can anyone advise if Checkpoint R80.20 can support ISP redundancy with PBR ( PBR presently configured to connect 2 links for wifi users)

Currently ISP redundancy for the main traffic is not configured in the setup and to want to achieve it now? Can anyone advise?

Thanks,

Jijo

 

0 Kudos
2 Solutions

Accepted Solutions

Re: ISP Redundancy with PBR

Jump to solution

Hi

I have made some tests with PBR and ISP (HA) redundancy in R80.30. 

PBR still works, meaning traffic is routed by policy rules, but NAT is not performed according "Hide behind gateway" outgoing interface.

NAT is using ISP redundancy primary interface and not real outgoing interface....

Regards

View solution in original post

Re: ISP Redundancy with PBR

Jump to solution

Thanks for your quick reply.

Understood the same now, if NAT not working then it would be an issue. So just to summarize, then this requirement is not feasible now, what I understand.

 

View solution in original post

0 Kudos
4 Replies
Admin
Admin

Re: ISP Redundancy with PBR

Jump to solution
ISP Redundancy and PBR are mutually exclusive features.
However, you can achieve some level of ISP Redundancy with PBR functionality starting in R80.30.
Specifically, you can create rules in terms of the default route.

Re: ISP Redundancy with PBR

Jump to solution

Hi Thanks for your reply. Just to make my question more clear, explaining the scenario here.

> Primary link at site , terminating via switches at one of the interface in checkpoint.Main traffic at the site is going via this link.

> Two other links configured via PBR for 2 different wireless connections at site ( due to a specific requirement)

> Noted the point that from R80.30, we could do some level of ISP redundancy in Checkpoint, but my question is in this scenario with total 3 links in total ( One main primary and other 2 PBR), can we configure a redundancy for the primary link for main traffic using the ISP redundancy feature in Checkpoint?

Thanks,

Jijo 

 

0 Kudos

Re: ISP Redundancy with PBR

Jump to solution

Hi

I have made some tests with PBR and ISP (HA) redundancy in R80.30. 

PBR still works, meaning traffic is routed by policy rules, but NAT is not performed according "Hide behind gateway" outgoing interface.

NAT is using ISP redundancy primary interface and not real outgoing interface....

Regards

View solution in original post

Re: ISP Redundancy with PBR

Jump to solution

Thanks for your quick reply.

Understood the same now, if NAT not working then it would be an issue. So just to summarize, then this requirement is not feasible now, what I understand.

 

View solution in original post

0 Kudos