- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All -
We are under progress to deploy a new solution,
Where we have two ISP and we are configuring ISP Redundancy so that certain (http &https) traffic uses specific ISP Link with sk32225
We will configure four interface configure on my firewall two external interface, one inside network and one DMZ network.
when my user will access any http and https traffic from internet they will pass throgh ISP1 and rest of the traffic will pass through with ISP-2 which is mention is Sk32225
we have some of Application in DMZ which are running on HTTPS and HTTP also.
i just want to confirm, if we will apply PBR for internal user to access DMZ subent with Https & Http services, they will reach DMZ subnet. will it work or not
I am attaching a diagram for your reference.
Abhishek,
your diagramm isn't readable, it's to small.
Can please more explain your need. Why do you need PBR to reching the DMZ network from internal ?
Normally the DMZ is reachable from internal via normal routing, ISP redundancy hould not have an affect on this.
Wolfgang
Using ISP Redundancy and the PBR feature together is not supported, see sk100500: Policy-Based Routing (PBR) on Gaia OS.
Can't seem to find any reference to support for ISP Redundancy w/ PBR being added in R80.30 vanilla or via Jumbo HFA and there seem to be two separate SK's saying it is not supported.
thanks for your update, but if we are applying PBR for my requirement, we need to create more than 200 PBR, which is difficult to manage. thats why i planing to edit Table.def file for sending perticular traffic from ISP-1 one and rest of the traffic we will send through ISP-2.
if we have any solution as per my requirement please suggest me.
Regards
Abhishek
I don't see why you need PBR for getting from Internal to DMZ or DMZ to Internal.
In order to send traffic over specific ISP-1 link then you would be adding 80 and 443 as HTTP and HTTPS to the no_misp_services_ports.
This will only affect traffic going out over the ISP Redundancy Links.
So this will NOT affect traffic from the DMZ to Internal or the Internal to the DMZ as they aren't involving the ISP Redundancy Interfaces.
As such I don't see what you need PBR for here.
I found from "From what's new R80.30"
Advanced Routing
Question is, does the first line meaning ISP redundancy => "Multiple ISPs" ?
As far as I tested Multi Hop PBR is a great tool but it kinds of "replace" the active/passive ISP redundancy mode, not the active/active mode.
I don't think that you can use ISP Redundancy & PBR together in 80.30 with beautiful results since the last routing decision that matters is the one from ISP Redundancy, at least until R80.10.
In new deployments I like to use multi hop instead of ISP Redundancy in case of active / passive since you can add many ISPs
Regards,
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 15 | |
| 14 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 5 | |
| 5 | |
| 5 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY