- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I try to find an alternative for isp redundancy with pbr.
sk167135 nearly describes that but for some reason here the internal network has a public-ip network and so there is no need to talk about hide-nat. I tested pbr so far but selecting hide-behind-gateway always uses the interface ip with the default route is used.
Thanks
Use instead of hide behind gateway option the VIP ip of the outgoing interfaces.
I think you now use automatic NAT, try to make static NAT rule and force it to use correct external IP
Hi
what exactly are you trying to accomplish? going out from specific ISP, without NAT?
so just don't enable NAT on this network object.
if I didn't understand, please elaborate a bit more.
Thanks
Did you try configuring your NAT manually?
Dummy object for the NAT with 0.0.0.0 or using Zones may help, but PBR and NAT has some limitations.
Maybe also explore Quantum SD-WAN with your local SE to see if it can help you?
How can I use manuel nat behind Interface upon failover? Alternative for ISP redundancy would require a NAT konfig that works no matter pbr route is active (--> ISP1) or it is down --> (ISP2) - (track pbr routes with monitored IPs)
As above historically you could use a host object 0.0.0.0 and it would pick the IP of the outbound interface.
Theoretically you could also assign a different zone to each interface and hence different NAT rules could be specified if needed.
You cannot mix PBR and ISP redundancy:
https://support.checkpoint.com/results/sk/sk167135
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY