Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
az26
Contributor

Policy based routing

Hi,

I’d like to ask for some advice regarding Policy-Based Routing (PBR), specifically whether using PBR can consume a significant amount of RAM and CPU on a Check Point firewall.

I have a ClusterXL setup (no VSX and no Multi-Domain Management), and we are going to have 2 different public subnets from the same ISP.

I have thought of 2 solutions on how to implement a setup where the 2 public subnets can be used simultaneously. 

 

1. Use the normal default route for all traffic and PBR for the second public subnet
The first public subnet would use the normal Internet routing configuration. For traffic originating from the second public subnet, or from specific private subnets, PBR would be used to route the traffic appropriately.

 

2- Use only one default route towards the internet and configure the second public subnet on a physical interface that's NOT facing the internet. I'll ask the ISP to configure a static route for the second public subnet pointing at link we already have with the first subnet. I have only one concern that is NATing for the second subnet, I think it should work with no problem.

 

Which setup you guys think is the best to be used in this case? and do you think NATing will work if I implement the second solution?

0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events