Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
velo
Collaborator

Second ISP

I have a pair of 6200s that I want to add a second ISP. It has a couple of VPNs configured on it to other Checkpoints I manage. My plan is this:

  1. Under the default route there is the option to add multiple next hops with with different priority. I will make the primary as priority as 1 and the backup as 10. I will choose to monitor the default gateway of each next hop.
  2. Setup Link Selection with probing under IPSEC

Any issues seen with this?

Thanks

0 Kudos
9 Replies
PhoneBoy
Admin
Admin

Does this gateway have any user traffic?
Possible you may need ISP Redundancy here.

0 Kudos
velo
Collaborator

Yes it has outbound user traffic (internet browsing)  Won't this be taken care of my a second default route? Can you clarify what you mean?

Thanks

0 Kudos
PhoneBoy
Admin
Admin

If you have user traffic, you'll likely have to deal with NAT (HIDE NAT in particular).
As NAT rules in SmartConsole cannot be made "per-ISP" (different NAT for different ISP), you need to use ISP Redundancy or Quantum SD-WAN.

0 Kudos
velo
Collaborator

Thanks. What is the section about "Configure the Cluster to be the DNS server" That makes no sense to me.. Seems like it's not relevant. 

To configure this on SMB firewalls is very easy, you just setup IPSEC link selection for VPNs, and NAT etc just work fine.

0 Kudos
the_rock
Legend
Legend

How many external IPs? Or to be precise, how many external interfaces?

Andy

0 Kudos
velo
Collaborator

Hey Andy

Just two. I have one now and am adding a second one.

Thanks

0 Kudos
the_rock
Legend
Legend

In that case, you may need ISP redundancy.

Andy

0 Kudos
velo
Collaborator

Thanks, I'm reading the docs. The DNS part doesn't make sense but I don't think that's relevant to my setup. I will see if I can lab it. 

Can you explain what I will need to do for outbound NATs? If I have the box ticked under "NAT" to hide internal networks behind Gateway, will this take care of all outbound NAT when there is a failover?

Thanks

Thanks

0 Kudos
the_rock
Legend
Legend

Yes, either you can do it that way or with manual nat, whichever works.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events