Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
FWNinja
Contributor

VPN Link Selection - Question

Jump to solution

Hi all,

I have other question for you.

I have configured VPN link selection with "Outgoing Route Selection -> When initiating a tunnel -> Operating system routing table".

"Operating system routing table" conteins PBR route? Or PBR route are in a separeted table?

 

Thanks and Best regards

Francesco

0 Kudos
1 Solution

Accepted Solutions
FWNinja
Contributor

Hi,

I will migrate Internet connection using PBR route.

For VPN route in Link Selection section it's configured "Outgoing Route Selection -> When initiating a tunnel -> Operating system routing table".

So, I want to know if Operating system routing table conteins PBR route that I will configure for the Internet connection migration.

Thanks

BR

Francesco

View solution in original post

0 Kudos
8 Replies
G_W_Albrecht
Legend
Legend

Have a good look into this : sk100500: Policy-Based Routing(PBR) on Gaia OS

0 Kudos
FWNinja
Contributor

Thanks for the link.

I already read sk link related to PBR but I cannot find anything relevant about my question.

Best regards

Francesco

0 Kudos
PhoneBoy
Admin
Admin
What is it you're actually trying to accomplish?
0 Kudos
FWNinja
Contributor

Hi,

I'm going to migrate Internet connection to a new ISP External interface.

I will use PBR to migrate subnet per sunbet.

I'd like to know if the OS routing table (in vpn link selection) conteins PBR route.

 

Thanks and Best Regards

Francesco

0 Kudos
FWNinja
Contributor

Hi,

I will migrate Internet connection using PBR route.

For VPN route in Link Selection section it's configured "Outgoing Route Selection -> When initiating a tunnel -> Operating system routing table".

So, I want to know if Operating system routing table conteins PBR route that I will configure for the Internet connection migration.

Thanks

BR

Francesco

View solution in original post

0 Kudos
FWNinja
Contributor
VPN Link Selection does not support PBR route for outbound vpn traffic. Checkpoint confirmed it!
0 Kudos
Maarten_Sjouw
Champion
Champion
VPN selection should use this setting indeed and you should set static routes for the remote sites that you have migrated to the new IP.
PBR has nothing to do with setting up the VPN, the traffic will not actually use the PBR as the traffic is not related to the VPN IPs themselves.
Regards, Maarten
0 Kudos
FedericoMeiners
Advisor

@Maarten_Sjouw It's important to note that PBR takes precedence before static routes, I have many customers with PBR intensive gateways that usually route by source causing VPN routing chaos.

____________
https://www.linkedin.com/in/federicomeiners/
0 Kudos