- Products
- Learn
- Local User Groups
- Partners
- More
Stop Babysitting Rules.
Go Agentic
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hey guys,
Hope someone can clarify this for me. Are there any commands to run on CP side that would show actual health of the ISP link? Client has ISPR configured, but they had been having issues lately when random users not being able to RDP or losing pings to some internal servers when connected to primary link, but if they connect to 2nd isp link, all works fine.
TAC provided cpstat fw and sv monitor options to check this, but thats not helpful here at all, it simply shows whether links are up or down.
Any other commands we could utilize to check say status of the link in the last 30 days?
Best,
Andy
Hey,
Just had remote with Tier3 guy from DTAC and he said command I gave fw -d isp_link to debug is the best, but otherwise, they dont sadly have a general IPS link health check commands. He advised to troubleshoot this when issue when someone is havinng the problem when connected to primary ISP link, so Im totally okay with that.
Best,
Anyd
Does the link flip-over? How does ISPR check if the link is healhty, does it ping only the default gateway?
If you only ping the DG it is not a proper health check, I always recommended to check the health of the IP after the DG. This will show in a traceroute
But on CLI it is indeed cpstat fw, to see if it is active/backup or down. Same output I think you can see in cpview.
If you want history if link failures they always have been logged in smartlog if you search for 'alerts'
There is never a failover, no. Ping to DG is fine, no issues there. I will check for alerts.
Andy
Ping to DG is a not a solid way to test an internet connection. Best would be to monitor extra hop (maybe DNS from ISP?) or second IP in traceroute. Make sure to make static route for this next hop ip to force it via the correct ISP link.
Trust me, there are no issues with DG or the link, Im 100% positive. Let me see what TAC guy gives Monday during remote.
Best,
Andy
So from check point point of view what is the issue? If you think link is OK but users complain maybe the link is just full? Maybe check cpview history if the link is full up or down. Check peak and compare what the isp gives for speed
Thats what we are trying to find out IF it is indeed CP issue lol
Thats why I asked if there are good commands to run that would show the health historically. I looked through cpview, but cant find good option, unless I missed it.
Andy
The network part where you can see the interfaces and the mbps tx and rx. Check historical if you see full isp link.
K, thank you...will check Monday.
Best,
Andy
Just had a quick look on customer's master fw and I dont see anything there related to ISP links. I do see stats for eth1, which represents, if you will, their primary ISP link, but no obvious issues that I can tell. Anyway, let me see what TAC guy says tomorrow.
Best,
Andy
Hey,
Just had remote with Tier3 guy from DTAC and he said command I gave fw -d isp_link to debug is the best, but otherwise, they dont sadly have a general IPS link health check commands. He advised to troubleshoot this when issue when someone is havinng the problem when connected to primary ISP link, so Im totally okay with that.
Best,
Anyd
Hi,
did you get any results, or have you found a procedure to track down the ISP redundancy issue?
We have two ISP links and when the primary link is active, it's showing the same behavior you're reporting, but only for FTP traffic and ICMP. The provider is promising that the line is okay. Swapping to the secondary, everything is fine.
The people on site are questioning the 6400, because another site in the same city and the same provider using a 6600 do not have problems at all.
Rgds from Germany
--Guido
Hey mate,
Not really, sorry : - (. TAC guy said you can go to cpview, software-blades, then vpn, and if you scroll down, then you see link failures option,but again, that ONLY shows you if link ever failed, NOT the actual health.
Little disappointing there is no better way, but hey, as that cheesy saying goes, it is what it is haha. Maybe this becomes available in R82, no clue.
Best,
Andy
consider replace ISPR with our Quantum SD-WAN.
with Quantum SD-WAN you will have clear visibility on the probing for each link with full sla results in real time and history, per steering / rule (traffic), clear events on link swaps, and much more functionality & granularity.
I get what you are saying, but thats sadly not an option at the moment.
Best,
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 23 | |
| 19 | |
| 9 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY