<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSEC VPN gateway traffic selection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-VPN-gateway-traffic-selection/m-p/103124#M10083</link>
    <description>&lt;P&gt;Hi Val,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The CP&amp;nbsp; GW version is R80.10.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Nov 2020 10:48:31 GMT</pubDate>
    <dc:creator>Dilev</dc:creator>
    <dc:date>2020-11-24T10:48:31Z</dc:date>
    <item>
      <title>IPSEC VPN gateway traffic selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-VPN-gateway-traffic-selection/m-p/103093#M10081</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having an issue with a vpn setup where we have a Checkpoint FW with one ISP line connected to it and a remote site (Juniper srx) with 2 ISP lines connected to it. We have 2 Ikev1 IPSEC vpn tunnels between the two sites that coming up(permanent tunnels enabled).&lt;BR /&gt;Our issue is that the traffic between the two sites seems to be going through both tunnels at the same time instead of one tunnel being the primary one and the second one acting as a backup/failover in case the primary tunnel goes down for any reason.&lt;/P&gt;&lt;P&gt;What is the mechanism Checkpoint uses to determine which of the two tunnels it is going to send the traffic through and how can we specify it?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 08:42:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-VPN-gateway-traffic-selection/m-p/103093#M10081</guid>
      <dc:creator>Dilev</dc:creator>
      <dc:date>2020-11-24T08:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN gateway traffic selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-VPN-gateway-traffic-selection/m-p/103123#M10082</link>
      <description>&lt;P&gt;Version fo CP GW?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 10:46:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-VPN-gateway-traffic-selection/m-p/103123#M10082</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-11-24T10:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN gateway traffic selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-VPN-gateway-traffic-selection/m-p/103124#M10083</link>
      <description>&lt;P&gt;Hi Val,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The CP&amp;nbsp; GW version is R80.10.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 10:48:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-VPN-gateway-traffic-selection/m-p/103124#M10083</guid>
      <dc:creator>Dilev</dc:creator>
      <dc:date>2020-11-24T10:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN gateway traffic selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-VPN-gateway-traffic-selection/m-p/103129#M10084</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/13924" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/html_frameset.htm?topic=documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/13924&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Look under "Link Selection with non-Check Point Devices" section.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Which part initiates VPN tunnel, Juniper or CP? If Juniper, you should look there first.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 11:03:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-VPN-gateway-traffic-selection/m-p/103129#M10084</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-11-24T11:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN gateway traffic selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-VPN-gateway-traffic-selection/m-p/104949#M10085</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We've tried the things suggested in the article, but we are still having issues with the traffic selection.&lt;/P&gt;&lt;P&gt;Currently, the traffic from the checkpoint is taking the backup tunnel to our SRX, instead of the primary one. How can we force it to use one tunnel over the other and switch to the second only if the traffic through the first one fails?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 10:44:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-VPN-gateway-traffic-selection/m-p/104949#M10085</guid>
      <dc:creator>Dilev</dc:creator>
      <dc:date>2020-12-10T10:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPSEC VPN gateway traffic selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-VPN-gateway-traffic-selection/m-p/104963#M10086</link>
      <description>&lt;P&gt;I suggest using VTIs with a routing protcol over it.&lt;BR /&gt;&lt;BR /&gt;What is known as "Route based VPN"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31012&amp;amp;partition=Basic&amp;amp;product=IPSec" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk31012&amp;amp;partition=Basic&amp;amp;product=IPSec&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check IPsec VPN admin guide for your version.&lt;BR /&gt;&lt;BR /&gt;Also you can check config guides for AWS or azure as reference.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 11:49:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPSEC-VPN-gateway-traffic-selection/m-p/104963#M10086</guid>
      <dc:creator>Juan_</dc:creator>
      <dc:date>2020-12-10T11:49:30Z</dc:date>
    </item>
  </channel>
</rss>

