Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
michaelyang123
Participant

About ISP Redundancy monitor

Hello Expert,

 

When I tested ISP Redundancy, I found that it is not compatible with PBR.

Here is structure.

1.PNG


So I changed to use two next hops on the static route, and use priority to divide the primary and the secondary.

2.PNG

I found out that the only way to checkpoint to make sure the route works is to make sure the next hop is viable.

For example, if I turn off Gi0/0 on S3 it switches to the second line for service, but if I turn off Gi0/1 on S3 the checkpoint continues to the first line without switching.

Is there a way to configure the first line to ping the IP of the external network? (transparent monitor)
For example, ping 8.8.8.8 through 30.30.30.30 to make sure that this line can reach the external network.


Thanks

8 Replies
_Val_
Admin
Admin

Before anything else, can you please state the appliance model and SW version in use?

_Val_
Admin
Admin

According to sk167135, PBR is not supported with ISP redundancy.

michaelyang123
Participant

Hi @_Val_ ,

Thanks for your reply.

I know PBR is not supported with ISP redundancy.

So I changed to use two next hops on the static route, and use priority to divide the primary and the secondary.

Is there a way to configure the first line to ping the IP of the external network? (like transparent monitor)
For example, ping 8.8.8.8 through 30.30.30.30 to make sure that this line can reach the external network.

---

All my device models are VE.

 

PhoneBoy
Admin
Admin

I believe this will do what you're after: https://support.checkpoint.com/results/sk/sk102848 

michaelyang123
Participant

Hi @PhoneBoy ,

I didn't use ISP redundancy because it's not compatible with PBR.

---

According to my setup

I thought the setup was to ping 8.8.8.8 via this path (30.30.30.30), but it turns out it is just the device that has to ping 8.8.8.8, regardless of the path!

3.PNG

PhoneBoy
Admin
Admin

This may be a limitation, I would check with TAC.

DeltaUnit
Explorer

you only need one default route - the ISP redundancy configuration is done using the smart console - Gateways and servers - open the gateway object - others tab - ISP redundancy. https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityGateway_Guide/Conten...

michaelyang123
Participant

Hi @DeltaUnit ,

 

Thanks for your reply.

Since I'm going to use PBR, I won't consider using "ISP redundancy" function because it's not compatible.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events