Re: ISP Redundancy failover, impact to outbound non FW hosts It now works!!!! Look at Checkpoint sk25152. It explains how to make the static nats for the primary interface not be used when it is down. It involves the use of dynamic objects in the NAT rules, dynamic commands as well a script updates to $FWDIR/bin/cpisp_update. I following the instructions on our FW. I then pulled the primary interface. The outgoing Email now used the static NAT to the 2nd interface. I confirmed I was able to send and receive Email. I tested this under both options, Load Balancing and Primary/Backup. |