- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have 2 node Cluster of Checkpoint 4400 running R80.20.
I will shortly be changing ISP but would like to run both ISP's IP addresses until I have migrated everything.
Can I have 2 interfaces set to External?
And if I can what implications will that have on routing?
Any help appreciated!
Thanks for your reply PhoneBoy,
So essentially if I add a new Clustered interface, set it to external in topology, my cluster will continue to use the current external as the default route until i change it to be the new one.
Before I change to the new one I would like to be able to migrate services to the new IP range. I assume I can just change the Static NAT for those services on the individual nodes? (Nodes are in DMZ)
Would it be good place to use build in feature - gateway properties -> other -> ISP redundancy?
No it wouldn't be a good idea to use the ISP Redundancy feature. Getting the DNS and NAT is a right pain if setting up properly. I really hoped that Check Point would drop the feature altogether with R80 Gateways.
For what is wanted here which is moving services over and then removing the origional link then a Second Line is fine.
You can move over services with known IP simply by putting routes on the Gateway that use the Second ISP as the next hop.
For Services with unknown IP that connect too/from then will have to wait till move the DG over
Hi there,
I never used ISP redundancy feature. Why it is so bad that you expected Checkpoint to remove it altogether?
I hoped that it would be removed as it is effectively unfinished. Didn't expect just hoped it would be.
Load Sharing still sends ALL outbound traffic that has to be Static NATed, ie Servers over the Fist Listed ISP link
Only Hide NAT is actually Load Shared across the two lines.
Guess what in Load Sharing you cannot actually specify which is the First Listed ISP link.
You are restricted too 2 lines
Remote Access VPN Client didn't work properly with the feature.
Even working with TAC then struggled to get to work properly and still not 100% convinced that did.
Track features not great.
It had the potential but was never progressed.
Is now a little bit above the Connect Control feature. Still there but not touched in ages, and never recommend to use,
The ONLY time where I would use is at a Branch Office where have two lines.
Used to build a VPN back to the Office where all Check Point so the Switchover with the Probing works.
NO Servers hosted at the Branch so ALL Traffic is simply set to be NAT behind the Gateway so can be Load Shared.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY