- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Team,
Is it possible to configure for internet traffic or IP range in destination, One of my Customer wants to route for particular VLAN traffic should use third internet link but customer environment have 30 routing entry for their enterprise network so in this case, I need to configure 30 PBR entry for the internal networks?
@PhoneBoy Agreed that solution provides for internet traffic through another ISP, when I put similar PBR for particular VLAN all the traffic including internal subnet also forwarded to ISP link, herewith I have attached simplified network overview.
Scenarios:
1. ISP 1 - Primary INT
2.ISP 2 - Specific user internet access (managers)
3.ISP 3 - Specific server segment internet access
Near Future expansion
4. ISP-4 SIP link for softPBX server
5.ISP-5 secondary internet going to participate ISP redundancy
I believe PBR table would be enormous also very hard to manage, Please suggest best practice to maintain less configuration to fulfill the requirement (please consider MPLS network will be used by users/servers to access some service from corporate network)
Hi
@PhoneBoy I have upgraded to R80.30 OS, So what is the best way to configure PBR. The best practice??
I understood, but the default route includes all the addresses(any), it would be much easier if there is an option in PBR for internet routes (Public IP addresses only). Please consider this in future releases.
Hi Mithu - Would like to know what you did to resolve the internet only issue, we are facing the same challenges.
Thanks,
Tim
Hello,
You have to create another PBR table which includes all your local network and static routes and apply that table before the 'internet only' pbr rule. It is very well explained in this post
Solved: Route specific subnet out second ISP interface - Check Point CheckMates
Regards
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 28 | |
| 15 | |
| 13 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 5 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY