- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Dear Team,
My customer is on R80.40 with 5600 HA mode firewalls.
The scenario is below :
1. Lan users connect to Internet after passing through Check Point firewall and then after passing through Check Point the traffic is IPSEC tunneled with ZScalar cloud proxy
2. Currently customer has 2 ISP Links and configured in Load sharing mode , Unfortunately one of the ISP's is frequently giving less amount of BW than it is supposed to this in turn creating latency issues to customer's internet traffic. Because of this reason customer manually changes the ISP redundancy percentages i.e gives maximum priority to second ISP
3. But this is in turn creating another problem i.e IPSEC tunnel with Z scalar gets disconnected and he should manually go to Link selection in Check Point and select the static IP of second interface.
Are we missing anything to make this work automatically with out manual intervention. Kindly help with solution.
Curious, do you have this option checked in the ISP Redundancy settings with respect to VPN?
Looks pretty self-explanatory to me.
If you want to use both interfaces at the same time for VPN, then you probably need to use this feature.
Whether it will work with Zscaler or not is a different question.
Curious, do you have this option checked in the ISP Redundancy settings with respect to VPN?
Hey Hi,
No it's not selected currently.
Sorry for late reply.
If you want VPN traffic to follow ISP Redundancy rules, then this setting needs to be enabled.
That should eliminate the need to change the Link Selection on failover.
Believe the route-based probing isn't relevant when using ISP Redundancy.
Hi,
Many thanks for swift reply. Got cleared about VPN settings in ISP redundancy with your explanation.
However, request you to have look and revert on the attached Image which explains about Route Based Probing option in link selection and it mentions relevancy about ISP redundancy Load sharing mode.
Looks pretty self-explanatory to me.
If you want to use both interfaces at the same time for VPN, then you probably need to use this feature.
Whether it will work with Zscaler or not is a different question.
Many thanks for the explanation.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 19 | |
| 11 | |
| 8 | |
| 6 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY