- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I'm planning to configure the ClusterXL with 4 internet connections and PBR, I would like to know if it will work also for the VPN IPSec, VPN Client, and NAT.
Regards
The appropriate Link Selection setting would be needed for the VPN to work properly.
Not sure what you mean by "NAT on the third connection" can you clarify?
Hi PhoneBoy,
thanks for your reply.
Let me describe better what I want to achieve:
The ClusterXL is the default gateway for all 4 VLANs.
Now, how can I implement all this?
Is there any drawback or limitation for the VPN traffic?
Thank you,
Hmm.. rather odd setup imho... but if you look at the Link Selection/reply from the same interface, that should cover inbound traffic. That said, I believe the PBR has some limitations that may be material to you. Not sure what version you are on, but those listed in SK100500 were still applicable to R80.40.
Properly setting the Link Selection and VPN community is required to ensure only the relevant VLANs are accessible and the VPN will transit the correct link.
You'll need appropriate PBR Routes for all of this for VLAN1-3.
Since you're talking about Default Route, make sure you're at least on R80.30.
VLAN2-4 should be able to talk assuming routes and Access Policy is defined appropriately.
You've not mentioned what should happen if one of these Internet connections fails.
The VPN would be most impacted by this, but I believe the other parts of this should work.
Hi PhoneBoy,
very good point "You've not mentioned what should happen if one of these Internet connections fails." - Just to make things easier, I'll implement some FHRP (VRRP or HSRP) as the next-hop for the PBR.
"Since you're talking about Default Route, make sure you're at least on R80.30." - I'm on R80.40 now 😊
Could you kindly share a configuration template for the PBR? 😁
Thank you
Sorry, I don't have a configuration template.
I would refer you to the following SKs for information:
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 14 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY