- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
I have a customer who has an HA pair set to Load-Sharing mode and is on R81.20. A VTI configuration with a third-party that is utilizing Ubiquiti devices. The firewalls are set as Load-Sharing in ISP Redundancy with the VPN check box cleared. The customer wishes to know the following.
How do they configure their route-based VPN to specifically use the secondary ISP connection? Their primary ISP has been having port flapping issues which is affecting the connection from the remote location's device to their network. Hence why they wish to do this. Any recommendations or things I should look out for? Any information would be appreciated.
Thank you
Sounds like they need to make sure secondary ISP link works right. If 1st fails, does other one take over?
Andy
The issue seems to be a hop along the path through one ISP compared to the other. It's pretty consistent, so they want to make the secondary connection the primary JUST for this vpn tunnel.
How is your "link selection" configured currently, believe there were some enhancements with this under R82 per:
You're right, that R82 enhanced link section is exactly what we would need for this too. I'll bring this up to the customer as they weren't planning on moving to R82 until December. I'll send this over to them to review. Thank you!
Until you go to R82, for R80.20 and higher, you can use the BestRoutingSenderIP config as noted in sk108600, Scenario 2. Since R80.30, IKEv2 is also supported:
https://support.checkpoint.com/results/sk/sk108600
I use this regularly for several customers with multiple upstream next-hops. You'll need a static route on the gateway for the remote peer to exit the interface you want towards the desired next hop.
After this is set, the IKE ID for 3rd party VPN and PSK will adjust accordingly.
Yep, that does work, used it before.
Andy
Would these changes revert after an upgrade to R82?
The changes are in the HKLM_registry.data file, which would not be carried over for upgrades (in-place or otherwise). They will remain in place for Jumbo HFA updates, however.
I would definitely back up the file, but @Duane_Toler is absolutely correct.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 19 | |
| 13 | |
| 12 | |
| 11 | |
| 9 | |
| 9 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY