<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SD-WAN + VPN Service-based link selection in SD-WAN</title>
    <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-VPN-Service-based-link-selection/m-p/196074#M156</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1920"&gt;@RS_Daniel&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;here you can find more information about the new Check Point SD-WAN solution via the Infinity Portal and Gateway SD-WAN Nano Agent.&lt;/P&gt;
&lt;P&gt;With the new &lt;SPAN class="mc-variable Vars_Other.tp_family_Quantum variable"&gt;Quantum&lt;/SPAN&gt; &lt;SPAN class="mc-variable Vars_Other.tp_sd_wan variable"&gt;SD-WAN&lt;/SPAN&gt; solution you can configure your &lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Gateway&lt;/SPAN&gt; / Cluster to steer traffic dynamically between the configured &lt;SPAN class="mc-variable Vars_SD_WAN.tp_sd_wan_links variable"&gt;WAN Links&lt;/SPAN&gt; based on the measured &lt;SPAN class="mc-variable Vars_Other.tp_isp_short variable"&gt;ISP&lt;/SPAN&gt; link quality. This does &lt;EM&gt;not&lt;/EM&gt; require dynamic routing configuration on your &lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;GW&lt;/SPAN&gt; / Cluster. With &lt;SPAN class="mc-variable Vars_Other.tp_sd_wan variable"&gt;SD-WAN&lt;/SPAN&gt; customers get the most efficient use of high-cost Wide Area Network connections and best user experience for consuming cloud-hosted services in branch offices.&lt;/P&gt;
&lt;P&gt;The &lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;GW&lt;/SPAN&gt; / Cluster sends different types of traffic through different &lt;SPAN class="mc-variable Vars_Other.tp_isps_full variable"&gt;Internet Service Providers&lt;/SPAN&gt; (&lt;SPAN class="mc-variable Vars_Other.tp_isps_short variable"&gt;ISPs&lt;/SPAN&gt;) based on application / identity and dynamic measurement of &lt;SPAN class="mc-variable Vars_SD_WAN.tp_sd_wan_link variable"&gt;WAN Link&lt;/SPAN&gt; characteristics. The &lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;GW&lt;/SPAN&gt; / Cluster applies the configured &lt;SPAN class="mc-variable Vars_Other.tp_sd_wan variable"&gt;SD-WAN&lt;/SPAN&gt; rules only if the &lt;SPAN class="mc-variable Vars_Other.tp_secpol variable"&gt;Security Policy&lt;/SPAN&gt; allows this traffic.&lt;/P&gt;
&lt;P&gt;After you install the &lt;SPAN class="mc-variable Vars_SD_WAN.tp_sd_wan_policy variable"&gt;SD-WAN Policy&lt;/SPAN&gt;, it becomes the main decision maker for traffic paths, traffic priorities, and so on for WAN connections. The &lt;SPAN class="mc-variable Vars_Other.tp_sd_wan variable"&gt;SD-WAN&lt;/SPAN&gt; policy makes these decisions based on the settings you configure in &lt;SPAN class="mc-variable Vars_CloudGuard.tp_infinity_portal variable"&gt;Infinity Portal&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;For additional information, see:&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Quantum-SD-WAN-Admin-Guide/Content/Topics-SD-WAN/Configuration-SD-WAN-Policy.htm" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Quantum SD-WAN Administration Guide - Configuring SD-WAN Policy&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Quantum-SD-WAN-Admin-Guide/Content/Topics-SD-WAN/GUI.htm" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Quantum SD-WAN Administration Guide - SD-WAN Service GUI&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk180605" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk180605: Quantum SD-WAN&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;SD-WAN Video's:&lt;BR /&gt;&lt;A href="https://youtu.be/T_FRz8GJWdQ" target="_blank" rel="noopener"&gt;Best Security in the context of SD-WAN&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/doFMs-3sfZg" target="_blank" rel="noopener"&gt;Application based traffic steering&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/lT8sz_mMLjk" target="_blank" rel="noopener"&gt;Understanding solution components&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/dy83VIe_oTA" target="_blank" rel="noopener"&gt;Management Architecture Details&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/AvNeZ2Jlh6Y" target="_blank" rel="noopener"&gt;Initial Deployment of SD-WAN environment&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/LTrR104mw0w" target="_blank" rel="noopener"&gt;Onboarding additional Security Gateways to SD-WAN&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/Pwbt0i-bd-Q" target="_blank" rel="noopener"&gt;Understanding outbound NATed traffic&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/7DwjIaP1s2Y" target="_blank" rel="noopener"&gt;Understanding inbound NATed traffic&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/JfCeIA0D_RE" target="_blank" rel="noopener"&gt;Configuring VPN Overlay&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2023 19:41:07 GMT</pubDate>
    <dc:creator>HeikoAnkenbrand</dc:creator>
    <dc:date>2023-10-24T19:41:07Z</dc:date>
    <item>
      <title>SD-WAN + VPN Service-based link selection</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-VPN-Service-based-link-selection/m-p/196054#M155</link>
      <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am working in a deployment for SD-WAN with Overlay VPN use case. Customer has many Internet connections and one MPLS between HQ and branchs. What we want to achieve is to send all internal traffic in clear text routed thorugh the MPLS connection.&lt;/P&gt;
&lt;P&gt;We were planning to use&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk56384" target="_self"&gt;&lt;SPAN&gt;VPN Service-based link selection&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp; to send the some traffic&lt;SPAN&gt;&amp;nbsp;routed through the MPLS link in clear-text and only if MPLS is DOWN, failover to encrypted VPN connections with Internet interfaces. We are ok until here.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The problem is that above this configuration, we wanted to work with SD-WAN to route traffic through specific Internet interfaces (encrypted) based on link monitoring parameter.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Wanted to ask if it is supported to work with SDWAN above a VPNA Service-based link selection scenario. Where only if MPLS clear text link fails, re route all traffic based on SDWAN. Or maybe if it is supported to work with MPLS clear text and Internet links encrypted with SDWAN only.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 16:56:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-VPN-Service-based-link-selection/m-p/196054#M155</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2023-10-24T16:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN + VPN Service-based link selection</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-VPN-Service-based-link-selection/m-p/196074#M156</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1920"&gt;@RS_Daniel&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;here you can find more information about the new Check Point SD-WAN solution via the Infinity Portal and Gateway SD-WAN Nano Agent.&lt;/P&gt;
&lt;P&gt;With the new &lt;SPAN class="mc-variable Vars_Other.tp_family_Quantum variable"&gt;Quantum&lt;/SPAN&gt; &lt;SPAN class="mc-variable Vars_Other.tp_sd_wan variable"&gt;SD-WAN&lt;/SPAN&gt; solution you can configure your &lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Gateway&lt;/SPAN&gt; / Cluster to steer traffic dynamically between the configured &lt;SPAN class="mc-variable Vars_SD_WAN.tp_sd_wan_links variable"&gt;WAN Links&lt;/SPAN&gt; based on the measured &lt;SPAN class="mc-variable Vars_Other.tp_isp_short variable"&gt;ISP&lt;/SPAN&gt; link quality. This does &lt;EM&gt;not&lt;/EM&gt; require dynamic routing configuration on your &lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;GW&lt;/SPAN&gt; / Cluster. With &lt;SPAN class="mc-variable Vars_Other.tp_sd_wan variable"&gt;SD-WAN&lt;/SPAN&gt; customers get the most efficient use of high-cost Wide Area Network connections and best user experience for consuming cloud-hosted services in branch offices.&lt;/P&gt;
&lt;P&gt;The &lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;GW&lt;/SPAN&gt; / Cluster sends different types of traffic through different &lt;SPAN class="mc-variable Vars_Other.tp_isps_full variable"&gt;Internet Service Providers&lt;/SPAN&gt; (&lt;SPAN class="mc-variable Vars_Other.tp_isps_short variable"&gt;ISPs&lt;/SPAN&gt;) based on application / identity and dynamic measurement of &lt;SPAN class="mc-variable Vars_SD_WAN.tp_sd_wan_link variable"&gt;WAN Link&lt;/SPAN&gt; characteristics. The &lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;GW&lt;/SPAN&gt; / Cluster applies the configured &lt;SPAN class="mc-variable Vars_Other.tp_sd_wan variable"&gt;SD-WAN&lt;/SPAN&gt; rules only if the &lt;SPAN class="mc-variable Vars_Other.tp_secpol variable"&gt;Security Policy&lt;/SPAN&gt; allows this traffic.&lt;/P&gt;
&lt;P&gt;After you install the &lt;SPAN class="mc-variable Vars_SD_WAN.tp_sd_wan_policy variable"&gt;SD-WAN Policy&lt;/SPAN&gt;, it becomes the main decision maker for traffic paths, traffic priorities, and so on for WAN connections. The &lt;SPAN class="mc-variable Vars_Other.tp_sd_wan variable"&gt;SD-WAN&lt;/SPAN&gt; policy makes these decisions based on the settings you configure in &lt;SPAN class="mc-variable Vars_CloudGuard.tp_infinity_portal variable"&gt;Infinity Portal&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;For additional information, see:&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Quantum-SD-WAN-Admin-Guide/Content/Topics-SD-WAN/Configuration-SD-WAN-Policy.htm" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Quantum SD-WAN Administration Guide - Configuring SD-WAN Policy&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Quantum-SD-WAN-Admin-Guide/Content/Topics-SD-WAN/GUI.htm" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Quantum SD-WAN Administration Guide - SD-WAN Service GUI&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk180605" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk180605: Quantum SD-WAN&lt;/SPAN&gt;&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;SD-WAN Video's:&lt;BR /&gt;&lt;A href="https://youtu.be/T_FRz8GJWdQ" target="_blank" rel="noopener"&gt;Best Security in the context of SD-WAN&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/doFMs-3sfZg" target="_blank" rel="noopener"&gt;Application based traffic steering&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/lT8sz_mMLjk" target="_blank" rel="noopener"&gt;Understanding solution components&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/dy83VIe_oTA" target="_blank" rel="noopener"&gt;Management Architecture Details&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/AvNeZ2Jlh6Y" target="_blank" rel="noopener"&gt;Initial Deployment of SD-WAN environment&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/LTrR104mw0w" target="_blank" rel="noopener"&gt;Onboarding additional Security Gateways to SD-WAN&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/Pwbt0i-bd-Q" target="_blank" rel="noopener"&gt;Understanding outbound NATed traffic&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/7DwjIaP1s2Y" target="_blank" rel="noopener"&gt;Understanding inbound NATed traffic&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://youtu.be/JfCeIA0D_RE" target="_blank" rel="noopener"&gt;Configuring VPN Overlay&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 19:41:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-VPN-Service-based-link-selection/m-p/196074#M156</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2023-10-24T19:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN + VPN Service-based link selection</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-VPN-Service-based-link-selection/m-p/196078#M157</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Currently all overlay traffic of our SD-WAN must go encrypted on all the lines. Private &amp;amp; public.&lt;/P&gt;
&lt;P&gt;In the future we might add support for such use case.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 19:54:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-VPN-Service-based-link-selection/m-p/196078#M157</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2023-10-24T19:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN + VPN Service-based link selection</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-VPN-Service-based-link-selection/m-p/196196#M158</link>
      <description>&lt;P&gt;May i ask why is it important to the customer to have cleartext traffic over the mpls?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 19:17:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-VPN-Service-based-link-selection/m-p/196196#M158</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2023-10-25T19:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN + VPN Service-based link selection</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-VPN-Service-based-link-selection/m-p/196441#M162</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/86692"&gt;@AmirArama&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;All the branchs are quamtum spark clusterXL gateways centrally managed and only HQ is regular quantum. We have found that VPN's are somewhat unstables on spark appliances specially with central management. We face strange VPN outage scenarios all the time. The VPN becomes DOWN without any change and we need to do one of these things to get it up again: pushing policy, failover, restart sfwd process, reboot appliance, etc...&amp;nbsp;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 18:30:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-VPN-Service-based-link-selection/m-p/196441#M162</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2023-10-27T18:30:05Z</dc:date>
    </item>
    <item>
      <title>Re: SD-WAN + VPN Service-based link selection</title>
      <link>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-VPN-Service-based-link-selection/m-p/196442#M163</link>
      <description>&lt;P&gt;I understand.&lt;/P&gt;
&lt;P&gt;That sound very strange.&lt;/P&gt;
&lt;P&gt;I suggest to open TAC and ask them to investigate it until they found the root cause. This shouldn't happend. And i'm not familiar with such issues.&lt;/P&gt;
&lt;P&gt;As always feel free to reach out to me for every SD-WAN related project.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 27 Oct 2023 18:49:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SD-WAN/SD-WAN-VPN-Service-based-link-selection/m-p/196442#M163</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2023-10-27T18:49:50Z</dc:date>
    </item>
  </channel>
</rss>

