- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I'm fairly new to Checkpoint and I've hit a scenario that I'm having trouble finding documentation on. I have a cluster with 3 ISPs. We do not have BGP so each of these 3 ISPs have a different subnet of public IPs. On our previous Juniper SRX firewalls we would source NAT our Guest WiFi out an address other than the primary IP on the interface. So far I can't find a way to handle this with multiple ISPs on checkpoint. I can see where I can tell a subnet to source NAT behind a specific IP, however I have 3 different IP address this traffic could source nat behind depending on which ISP we are using at the time. We also currently use PBR to route this traffic out one of what would be our backup ISPs.
I see a couple of options here:
That's actually what we are trying to avoid, we don't want to use the IP address of the interface. I've got that working fine. It's when we want to use a different IP that things are breaking.
Then your only option is a Dynamic Object that you manage OR a static host object.
Have you tried NAT statements with each interface assigned/representing a different "zone" ?
That I had not and I was hoping to avoid placing each ISP into it's zone since it's has it's own set of pitfalls that we've had to deal with on Juniper for years.
Am curious what issues you ran into with this, just for my own edification.
Not so much issues, but it was a lot of extra administrative overhead with additional firewall and NAT rules.
I will say the biggest pitfall we ran into was with VPN since they each had their own security zone due to other Junos limitations. Even though we ran iBGP on the tunnels, if we failed over any sessions would get interrupted since that traffic was now technically to and from different zones.
I don't believe we will have this limitation since Zones were not even supported until R8x and the VPN code has been there from the earliest days of the product.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY