- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters
E1: How AI is Reshaping Our World
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi
- We are having open server(81.10), where isp redundancy is enabled in load sharing mode.
- interface to access the Internet (first internet provider)
-interface with PAT on 25 and 443 ports (second prvider)
I need to disable ISP redundancy so that users use only one provider to access the Internet, but when I do this, the interface with the PAT stops responding on ports 25 and 443. At the same time, these requests are displayed in the logs with the status accepted
Any ideas what's going on?
For @G_W_Albrecht’s benefit: PAT == Port Address Translation (a specific NAT use case).
When you say “not work” what is the precise behavior?
I suspect what you’re running into is an asymmetric routing behavior caused by disabling ISP Redundancy.
You can verify this by running a tcpdump on the ISP1 interface when you try to access ports 25/443 from ISP2.
If this is the case, the only solution is to use Policy-Based Routing.
Specifically, you’d create a policy route that routes traffic from wherever the ultimate destination of 25/443 traffic is to route out ISP2.
Not sure how this will work with ISP Redundancy, though.
This is not clear to me - ISP 2 has an interface with EPS PAT (Policy Assignment Table) ?
For @G_W_Albrecht’s benefit: PAT == Port Address Translation (a specific NAT use case).
When you say “not work” what is the precise behavior?
I suspect what you’re running into is an asymmetric routing behavior caused by disabling ISP Redundancy.
You can verify this by running a tcpdump on the ISP1 interface when you try to access ports 25/443 from ISP2.
If this is the case, the only solution is to use Policy-Based Routing.
Specifically, you’d create a policy route that routes traffic from wherever the ultimate destination of 25/443 traffic is to route out ISP2.
Not sure how this will work with ISP Redundancy, though.
When i say not work i mean interface with ip address(which i use to mail service) stop answering on icmp and 443 outside with disable isp redundancy.
I mean if i disable isp redundancy users go to internet with default route, but why it's take some effect on different interface?
i use some policy based routing to route from dmz to lan btw
The routing table is “global” meaning it applies to every interface.
ISP Redundancy changes the default behavior for certain traffic.
With your specific ISP Redundancy configuration, traffic that is sent to the PAT address/ports on ISP2 will be sent out through ISP2.
Without ISP Redundancy, the reply traffic will follow the default route, which is ISP1.
But…you’re telling me you’re trying to access the ISP2 PAT address/port from internally?
That’s a beast of a different color; you’re basically doing hairpin NAT.
To solve THAT issue, see: https://community.checkpoint.com/t5/Security-Gateways/Traffic-flow-in-between-C-to-S-via-Firewall-Ho...
Hi, i mean when i disable isp redundancy, my interface with PAT don't answer to icmp and 443 port requests from outside. From inside it answer to icmp without any problem, i didn't get how ISP redundancy affect on icmp request to interface with static ip
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY