- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: PBR and nat
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PBR and nat
Hello,
I try to find an alternative for isp redundancy with pbr.
sk167135 nearly describes that but for some reason here the internal network has a public-ip network and so there is no need to talk about hide-nat. I tested pbr so far but selecting hide-behind-gateway always uses the interface ip with the default route is used.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Use instead of hide behind gateway option the VIP ip of the outgoing interfaces.
I think you now use automatic NAT, try to make static NAT rule and force it to use correct external IP
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
what exactly are you trying to accomplish? going out from specific ISP, without NAT?
so just don't enable NAT on this network object.
if I didn't understand, please elaborate a bit more.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did you try configuring your NAT manually?
Dummy object for the NAT with 0.0.0.0 or using Zones may help, but PBR and NAT has some limitations.
Maybe also explore Quantum SD-WAN with your local SE to see if it can help you?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How can I use manuel nat behind Interface upon failover? Alternative for ISP redundancy would require a NAT konfig that works no matter pbr route is active (--> ISP1) or it is down --> (ISP2) - (track pbr routes with monitored IPs)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As above historically you could use a host object 0.0.0.0 and it would pick the IP of the outbound interface.
Theoretically you could also assign a different zone to each interface and hence different NAT rules could be specified if needed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You cannot mix PBR and ISP redundancy:
https://support.checkpoint.com/results/sk/sk167135
If you like this post please give a thumbs up(kudo)! 🙂
