- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi CheckMates,
I’m exploring a design where a Check Point gateway connects to two ISPs. The client’s requirement is:
From my understanding, this would involve:
Where I’m unsure:
Has anyone here implemented something like this? I’d love to hear if this approach is solid, or if there’s a better way to achieve subnet‑specific ISP preference with automatic failover and zero human intervention.
The fact you're talking about LAN/WLAN means you're discussing SMB appliances.
Generally ISPR and PBR aren't supported together: https://support.checkpoint.com/results/sk/sk167135
Hi @PhoneBoy
Thanks for pointing that out. I actually wasn’t aware of that SK, so I’ll definitely look into it. Just to clarify, this setup is on enterprise Gaia gateways, not SMB appliances (I only used “LAN/WLAN” to describe internal segmentation).
The client’s requirement is zero human intervention in case of ISP failure, but they also want subnet‑specific steering (LAN → ISP‑1, WLAN → ISP‑2) under normal conditions. From what you’re saying, it sounds like ISP Redundancy and PBR can’t be combined, which raises the question:
You don't need ISP Redundancy for this, you can just use Multiple Default Routes with ECMP and PBR.
However, I don't think you can define a different NAT for different ISP with this configuration.
You can do this with Quantum SD-WAN, though.
The best way to achieve your need is to use SD-WAN. SQ-WAN does all the magic, using both ISPs, sent traffic from network A via ISP A and traffic from network B via ISP B. And if one ISP is failing everything is sent via the other. It's simple to configure with SD-WAN policy.
Hello,
You can fix your issue with SKs without any manuel configuration when ISP link down.
For Hide Nat: https://support.checkpoint.com/results/sk/sk174197
For Static Nat: https://support.checkpoint.com/results/sk/sk25152
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY