- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- add static route to 1450
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
add static route to 1450
hello im trying to add a static route to my checkpoint but the route is showing inactive . i dont see anywhere to enable it . what am i missing ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Try it using CLI, see Check Point 700/900/1400 Appliance Technical Reference Guide R77.20.87 p.432ff for details!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If the next hop is not on a directly connected network it won’t necessarily be active.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have something similar on 1570 dual internet (WAN primary cell0 secondary). After a few firmware updates (requested by CP support), all the traffic goes over LTE, and on WAN only ping probes (successful). WAN is primary active, any routing over wan (GUI/clish) ends with the inactive state. Default gateway over WAN is not visible on gui/clish, only over LTE (cell0). WAN is not answering ping requests. The only traffic is the ping probe by system (answered) and the probe state is green for all servers.
But "route add target_ip gw gw_ip" from linux - works. Route appears in gui as a system route and appliance works perfect (until interface down/restart).
Any idea how to force WAN to work, without forcing it at system level? By the way, where is the best place to place ifup-WAN command?
I guess about /31 netmask on WAN, but it is now common ...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would involve TAC here...
