- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: PBR With Multiple Tracking
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PBR With Multiple Tracking
Hi, how to configure PBR for redundancy automatic,i try Priority but not functioning.
Regards
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@quanglnh You can do this with Multi Hop PBR from 80.30 onwards
https://www.linkedin.com/in/federicomeiners/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A network diagram of what you're trying to do would be helpful.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
if you want to use two external connectivity and have an automatic backup if you loose one of them ( if I understand correctly) probably you need to implement ISP redundancy , policy base routing wont work in that way
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
this is the diagram.
User A connect to internet to ISP A
User B connect to internet to ISP B
User C connect to internet to ISP C
When ISP A is down automatic failover to ISP B or ISP C configured with priority is not functioning.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How would the gateway determine ISP A is down?
To do that, you'd need to have a reachability test (such as Ping)--something our PBR doesn't currently support.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
yes i understand, there is developed for coming soon pbr support this ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe it's planned, yes, but don't have an exact timeframe.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
some date estimated for this ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It appears there is a customer-specific release that offers this functionality.
Please check with your Check Point office.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
i question for the specific release with Check Point Office and respond not exist this.
Regards
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Contact me privately with who you're working with.
I'll connect the dots on the backend.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A little-known feature of ClusterXL may be able to help here; ClusterXL can be configured to test connectivity to upstream IP addresses with ping, and initiate a failover based on loss of reachability to the pinged hosts. There could be a very different Gaia PBR configuration on the standby member that takes over as a result. See:
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Tim,
According to sk100500:
PBR is supported in the following clusters:
- ClusterXL High Availability
- ClusterXL Load Sharing Unicast
- ClusterXL Load Sharing Multicast
- VRRP
Note:
PBR must be configured on each of the cluster members individually, and the configuration must be identical.
Can you shed some light if the above statement is correct or is it negated by the sk35780?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'd say the later SK is probably more correct and the PBR configs should match. I don't think ClusterXL will be able to actually tell if the PBR configuration is different between the cluster members (same way it can't tell if regular IP routing is different between them), but it may cause issues with how connections are represented between the members via state sync. Trying a different PBR config between different cluster members will probably work but will most certainly not be supported.
CET (Europe) Timezone Course Scheduled for July 1-2
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello! I have the same question! Is there any workaround for now? There past one year since first question..... How to achieve same functionality as on ip sla + track on cisco in PBR?????
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please check with your local office about the customer-specific release I mentioned.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is recommended versus using the customer releases previously mentioned.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi PhoneBoy,
I have a situation that need to use tracking host too. Let say from my Check Point Firewall, i have 2 connection to remote site. 1 is primary and 1 is backup. I want to track if primary connection are down (track by ping or something else) all connection to remote site will automaticly change to thê backup connection. And if primary connection up again, then all connections automaticly move back to primary connection. Can we do that with R80.10 or i have to upgrade to R80.30 ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@quanglnh You can do this with Multi Hop PBR from 80.30 onwards
https://www.linkedin.com/in/federicomeiners/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thanks Federico Meiners, I will check on this
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Federico,
How would NAT work in such situation ?
Can we have 2 Hide NAT configured if we have 2 ISP links ?
And let PBR use corresponding external interface IP for NAT'g ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Federico,
Do you have some scripts for example?
Regards
Yisus
