Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
JaySon_2021
Contributor
Jump to solution

Policy Based routing with reduntant ISP links

We have an HA firewall pair, and 2 ISP links. We want to utilize Policy based routing AND have traffic fail-over completely to either ISP1 or ISP2 if the circuit goes down.

Example:

- Net_10.1.1.0/24 goes through the Checkpoints and out ISP1

- Net_192.168.1.0/24 goes through the Checkpoints and out ISP2

If ISP1 goes down, then both Net_10.1.1.0/24 and Net_192.168.1.0/24 will be sent out ISP2, and vice versa.

Is this possible with PBR?

Thanks

0 Kudos
2 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

That should be possible with PBR, yes.

View solution in original post

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Hey Jeff,

Check out below post I made before holidays.

https://community.checkpoint.com/t5/Security-Gateways/ISP-redundancy-PBR-sd-wan-question/m-p/265222

Best,
Andy
"Have a great day and if its not, change it"

View solution in original post

0 Kudos
11 Replies
PhoneBoy
Admin
Admin

That should be possible with PBR, yes.

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Hey Jeff,

Check out below post I made before holidays.

https://community.checkpoint.com/t5/Security-Gateways/ISP-redundancy-PBR-sd-wan-question/m-p/265222

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
CheckPointerXL
Advisor
Advisor

did i study how to apply nat? in case of zone+r82 pay attention and take a look here https://support.checkpoint.com/results/sk/sk184176

0 Kudos
the_rock
MVP Diamond
MVP Diamond

Hey Jeff,

Hope link I shared helped?

Happy weekend!

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
JaySon_2021
Contributor

Yep. Helped clarify things. Appreciate it.

the_rock
MVP Diamond
MVP Diamond

For you, no charge...EXCEPT iphone charge. Thats my CORNY joke Im sure everyone is sick of lol

Anyway, yea, you can definitely open TAC case, though Im positive they will tell you the same thing.

For reference:

https://support.checkpoint.com/results/sk/sk167135

 

 

 

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
the_rock
MVP Diamond
MVP Diamond

Be free to message me directly any time, I have a very good lab set up, so most things can be tested.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
WiliRGasparetto
MVP Diamond
MVP Diamond

Yes, PBR should allow that

0 Kudos
the_rock
MVP Diamond
MVP Diamond

The catch is...would allow that, but PBR ONLY...NO ISPR involved : - )

Together, wont work.

Best,
Andy
"Have a great day and if its not, change it"
0 Kudos
JaySon_2021
Contributor

Thanks all for the responses. As I am getting mixed responses perhaps a TAC case is best.

Regards,

0 Kudos
Chris_Atkinson
MVP Platinum CHKP MVP Platinum CHKP
MVP Platinum CHKP

Their is conceptual & feature naming...

ISP redundancy doesn't necessarily mean you are using the Check Point feature by the same name where PBR is a limitation.

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events