- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi, engineers, I have a problem. When ISP redundancy is configured in the primary/backup mode, and I switch the link to the backup link, the NAT mapping address is still the public address of the primary link, not the public address of the backup link.When I change the Network address Hide to the Gateway and the main link to the backup link, there is no NAT mapping error.
With ISP Redundancy then if you want it to work then all of the Hide NAT should be configured as Hide Behind Gateway.
I believe from your update
When I change the Network address Hide to the Gateway and the main link to the backup link, there is no NAT mapping error.
That you have specified an IP address to Hide behind when you have the issue?
This is an incorrect configuration. If you configure the IP of the Primary Link then that setting is NOT updated by the ISP Redundancy and so will continue to NAT Traffic with the IP Configured.
ALL Hide NAT for it to work with the ISP Redundancy needs to be configured as Hide Behind Gateway in which case as you see then it will start to NAT with the Backup Link IP of the Gateway as the NAT when fail over.
http://supportcontent.checkpoint.com/documentation_download?id=12314
How to configure ISP Redundancy - Does seem to be very slow
For example, if I manually configure the static NAT rule this way, when switching from the main link to the backup link, the address of the network accessing the external traffic map will always be the address in the first NAT rule.Is that right?
Can't static NAT be configured manually?I can only hide the Intranet address behind the gateway, is that right?
That is correct as that will be first NAT that is matched in terms of Source, Destination
Covers how to do Static NAT using Dynamic Objects to represent the ISP.
Static NAT ALWAYS goes out over the first ISP in a Load Sharing so effectively is Primary/Backup anyway.
However is problematic at best and unreliable.
I would only use ISP Redundancy where not publishing Services, ie you don't need to do any Static 1:1 NAT.
If you need the resilience the better to go with an External Solution that can do the routing.
I was really hoping with R80 code that would have got rid of it as isn't reliable enough with my experience (including working with TAC) so either needs removing or needs some actual work doing to make it work reliably.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY