- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
According to sk25152, it is necessary to make modifications to the cpisp_update script in order to manage static NAT when ISP Redundancy is enabled. However, during my troubleshooting process, I discovered that this script is not compatible with R81.10 and is not supported by the sk article either.
Due to the absence of the dynobj_cache table in R81.10, it is not possible to make the necessary decision. Therefore, I am curious about the alternative methods available for controlling Static NAT when ISP redundancy is enabled.
TIA
Blason R
As far as I know, this script is still valid.
In any case, it's probably worth engaging the TAC.
Nope it is not - That exact an issue I faced this morning and I tried flushing the dynobj_cache table and it says no such table exists. That means this script will not work
I have custom script R&D gave me last year for R81.10, can send it to you if you prefer, not sure if it would work though.
Andy
Perhaps by examining the script, one may gain an understanding, as it is a straightforward bash script.
Below is the link to it, not sure if you need to create an account to get it
Andy
https://andybee.sharefile.com/d-s9916ebbac8924613aba43487841be395
That is right - yeah.
It is not allowing me download and it needs a account.
If you can send me your email in direct message, I can provide the link that way, and for that you 100% dont need an account.
Andy
Sent
you should have it now, I sent it back
Andy
Got it - Thanks.
So just replace the entire script with this one?
Yes sir. Make sure to backup the original file of course.
Andy
Any luck?
Havent had a chance to replicate it. Let me do that in a day or two and revert
K, no worries, take your time, hope it works.
Andy
have same issue.....so the script was changed and no sk telling us that?
Customers having R81 still work....fresh setup under R81.20 no chance (HA....manual nat)
Message me directly, I will send it to you. I have no clue if it was changed...I cant be 100% sure, but I would say 90% it was not modified. The only reason why we got it was due a client having really weird problem described in below post.
Best,
Andy
Responsed to your message mate. Ping me back if you need clarification.
Best,
Andy
Update from TAC: sk25152 not supportet from R81.10 upwards. Supportet workaround would be using manual nat rules with zone in destination field.
Hi, but how should we do it? do we still need to update the script? if we add zone to destination what will be the translated source field in the NAT rule, we have 2 addresses for ISP
Are there any news to this? The sk mentions the versions R80.40 (EOS), R81 (EOS), R81.10, R81.20. Is the sk updated and the script works for R81.10 and above?
As far as I know, this script is still supported.
If it's not working, I suggest involving TAC.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
10 | |
8 | |
6 | |
5 | |
5 | |
5 | |
5 | |
5 | |
5 | |
4 |
Wed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksWed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY