Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
ChoiYunSoo
Contributor

I want to use PBR function based on Domain in checkpoint

Hi

 

I recently had a meeting with a customer and received inquiries and requests about whether CheckPoint supports the domain-based PBR function.

 

So I checked 'sk167135' and ran an test and I got a positive result.

However, since the SK document I saw requires enabling the hidden function, I am concerned that it will affect firewall performance and other functions.

Can you tell us about the cases or problems of using the above SK in actual customers?

 

The simple configuration and the test I conducted referring to the SK document are as follows

 

1. Enable hidden features 

 --> Possible to set PBR based on firewall rule number

2. Set FQDN policy in Smart Console and install policy

3. PBR setting based on rule number

4. Based on the figure below, general external communication is set to flow to ISP No. 1, and traffic matching the domain-based PBR rule flows to ISP No. 2, and I have confirmed that it operates normally.

 

1.png

 

2.png

 

3.png

 

 

 

0 Kudos
1 Reply
Chris_Atkinson
Employee Employee
Employee

Caveats are documented in sk167135.

Other customers may opt to explore Quantum SD-WAN (sk180605) depending on their use cases.

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events