Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
madu1
Participant

NAT with two ISP lines

I've just added a new/second ISP line to my gateway and made this my primary ISP line.  ISP Redundancy is configured.

LAN traffic to the Internet leaves via the default gateway of ISP line 1 - the new line.  All good.

I still have a load of servers with static NAT on what is now the secondary ISP line.  These no longer work.  Tcpdump shows traffic arriving from the Internet via ISP line 2, but return traffic routes out via the default gateway on ISP 1.  Asymmetric routing...

How do I get this traffic to return via the interface it arrived on - back via ISP 2?

I've got other gateways with the same dual ISP configuration, and they work fine. Return traffic goes back out via the interface from which it arrived.  But not this gateway.  Any ideas why not and how to fix it?

0 Kudos
5 Replies
Chris_Atkinson
Employee Employee
Employee

Are all the gateways on a common version & JHF level?

CCSM R77/R80/ELITE
0 Kudos
madu1
Participant

Hi Chris,

Yeah, R81.20 Take 26 (cluster).

0 Kudos
the_rock
Legend
Legend

Do you have simple diagram?

Andy

0 Kudos
PhoneBoy
Admin
Admin

So they're all Check Point gateways and one set of them is having an issue?

0 Kudos
Lesley
Advisor
Advisor

This will give guidance I suspect:

https://support.checkpoint.com/results/sk/sk25152

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events