- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hi,
We are facing the issue with No.of PBRs,
Scenario... We have Juniper Switch with Virtual routers... we have installed Checkpoint IPS between Juniper Firewall and Juniper Switch... and we are routing the traffic through Checkpoint using PBR.
Support person not recommending more PBR(No.of PBR are 15)
Is it really limitation from Checkpoint 80.10? any suggestions please...
Thanks
Bala
Gaia ultimately pushes these rules to kernel so same limitations should apply either way. Please open a RFE request if you need 2500 PBR rules to be supported in Gaia.
There is no limit of PBR rules. Check Point officially declares in sk100500 that "You can define many Policy Rules."
Check Point does not note how many, but many for me means that only 15 PBR rules should be no issue at all.
Hello Danny,
We have a similar situation with one of our clients, the only issue is "many" in our case means we need 2500 PBR.
Check Point advised that "many" means 1024 only, so we have to go for a Linux PBR solution.
These routes will only stay for 3-6 months and will go to a single DG once the local network migration is complete.
My question is; will all limitations still apply if we implement PBR via Linux commands and 2500 individual rules?
do you foresee any challenges in doing this or any work around that can be helpful, Please?
Thanks
Hello All,
Can anyone please reply to the above question if they know about this, please?
Thanks
If you're trying to modify PBR with Linux commands (via expert mode) on the gateway, that is most definitely not supported.
If you're implementing the PBR on an external device, that's up to the external device.
What version/JHF are we talking about here?
Thanks for your reply.
we had a TAC case opened with ref:6-0003441780, and it was advised that the Linux commands could be used.
It was our SD who was involved with CP TAC, but I will confirm the current version asap.
Thanks
It depends on where the PBR limit is coming from (the Linux kernel or the Gaia configuration DB).
That might be a question for TAC, though I am also asking out of band.
Ok, Thanks for that. I did open a new TAC case, but no response yet. please let me know if you find out anything.
Thanks
TAC will ultimately tell you the same thing that @Sundeep_Mudgal answered as his team in R&D is responsible for PBR functionality in Gaia.
Recommend raising this requirement with your local Check Point office.
Its R80.40 T180
Gaia ultimately pushes these rules to kernel so same limitations should apply either way. Please open a RFE request if you need 2500 PBR rules to be supported in Gaia.
Thanks for the info @Sundeep_Mudgal
@Sundeep_Mudgal , it seems the RFE is a general feature request and might not be implemented. can a custom hotfix be provided if we contact local CP or a request via TAC?
While it wouldn't hurt to file an RFE, this request should be handled through your local Check Point office.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
17 | |
12 | |
7 | |
6 | |
6 | |
6 | |
6 | |
5 | |
3 | |
3 |
Fri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAThu 18 Sep 2025 @ 02:00 PM (EDT)
Bridge the Unmanaged Device Gap with Enterprise Browser - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY