- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
We have an HA firewall pair, and 2 ISP links. We want to utilize Policy based routing AND have traffic fail-over completely to either ISP1 or ISP2 if the circuit goes down.
Example:
- Net_10.1.1.0/24 goes through the Checkpoints and out ISP1
- Net_192.168.1.0/24 goes through the Checkpoints and out ISP2
If ISP1 goes down, then both Net_10.1.1.0/24 and Net_192.168.1.0/24 will be sent out ISP2, and vice versa.
Is this possible with PBR?
Thanks
That should be possible with PBR, yes.
Hey Jeff,
Check out below post I made before holidays.
https://community.checkpoint.com/t5/Security-Gateways/ISP-redundancy-PBR-sd-wan-question/m-p/265222
That should be possible with PBR, yes.
Hey Jeff,
Check out below post I made before holidays.
https://community.checkpoint.com/t5/Security-Gateways/ISP-redundancy-PBR-sd-wan-question/m-p/265222
did i study how to apply nat? in case of zone+r82 pay attention and take a look here https://support.checkpoint.com/results/sk/sk184176
Hey Jeff,
Hope link I shared helped?
Happy weekend!
Yep. Helped clarify things. Appreciate it.
For you, no charge...EXCEPT iphone charge. Thats my CORNY joke Im sure everyone is sick of lol
Anyway, yea, you can definitely open TAC case, though Im positive they will tell you the same thing.
For reference:
https://support.checkpoint.com/results/sk/sk167135
Be free to message me directly any time, I have a very good lab set up, so most things can be tested.
Yes, PBR should allow that
The catch is...would allow that, but PBR ONLY...NO ISPR involved : - )
Together, wont work.
Thanks all for the responses. As I am getting mixed responses perhaps a TAC case is best.
Regards,
Their is conceptual & feature naming...
ISP redundancy doesn't necessarily mean you are using the Check Point feature by the same name where PBR is a limitation.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY