- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026
Inception is On!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Good afternoon.
We have two routers that are up to CheckPoint. Traffic can come from both routers. The traffic can be from users who have a known ip address and users who have an unknown ip address.
In case the traffic comes from a known address, we can route it back the same way using static routing. Default route we have configured for the first router, so if the traffic with unknown address comes from the first router, it goes the same way.
But what if the traffic with an unknown address comes through the second router? Is there any way to set it to go the same way? Has anyone encountered this problem?
Afaik, every transmitted package has a source and destination IP - i never saw a package with unknown IP 😉 If you use IA, it is easy to match known users in rules different to unknown users.
Unfortunately we don't use IA, so we would like to redirect traffic in some other way.
Why not decide upon known / inknown IP ?
The point is that if traffic with an unknown address came through the first router, we have to send it back through the first router.
If the traffic came through the second router, then we must send it also through the second router.
We have static routes that send traffic with an address known to us through the necessary routers. And we have a default route that sends all traffic with an unknown address through the first router. But how do we send traffic with an unknown route through the second router?
Switch to only known IPs or use IA.
So IA can help us with that?
No, bad idea - will not help here.
Let the routers do the NAT !
Good idea, why didn't I think of that right away.
Thanks
Some missing details on your posting, so let me tell you how we're set-up. Maybe it will give you ideas.
In our DC's we have also two internet sources, and those routers have a BGP with the ISP and in between them.
On the LAN side of the Internet routers, we have an HSRP, and the CheckPoint GWs are in that Public range.
Routing respects the path that the externals reached to us, so nothing needs to be done on CheckPoint side.
So if I have to transpose that to your case, I would say that you might be getting through if you fix the routing between the two Internet boxes .
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 23 | |
| 21 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 4 | |
| 2 | |
| 2 | |
| 2 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY