<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPsec VPN termination on Loopback interfaces -R80.40 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-termination-on-Loopback-interfaces-R80-40/m-p/99151#M10375</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I am planning to create a loopback interfaces on my HA cluster with same Public&amp;nbsp; IP to terminate the IPsec VPN tunnels. It is required as I am having private IP address on external interface and I don't want to NAT the IP on Internet router.&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;1. Is that setup feasible , Shall I give the same public IP on both the members as loopback interfaces are not a part of cluster.&lt;/P&gt;&lt;P&gt;2. How would I choose the loopback interface IP&amp;nbsp; as an&amp;nbsp; Peer IP under Gateway Cluster properties -&amp;gt; IPsec VPN -&amp;gt; Link Selection I don't see an option to set this IP to be used as VPN peer IP for my third parties.&lt;/P&gt;&lt;P&gt;3. How this loopback interface&amp;nbsp; chooses physical interfaces to route its traffic&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Anshu Bathla&lt;/P&gt;</description>
    <pubDate>Thu, 15 Oct 2020 06:08:46 GMT</pubDate>
    <dc:creator>ab</dc:creator>
    <dc:date>2020-10-15T06:08:46Z</dc:date>
    <item>
      <title>IPsec VPN termination on Loopback interfaces -R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-termination-on-Loopback-interfaces-R80-40/m-p/99151#M10375</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I am planning to create a loopback interfaces on my HA cluster with same Public&amp;nbsp; IP to terminate the IPsec VPN tunnels. It is required as I am having private IP address on external interface and I don't want to NAT the IP on Internet router.&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;1. Is that setup feasible , Shall I give the same public IP on both the members as loopback interfaces are not a part of cluster.&lt;/P&gt;&lt;P&gt;2. How would I choose the loopback interface IP&amp;nbsp; as an&amp;nbsp; Peer IP under Gateway Cluster properties -&amp;gt; IPsec VPN -&amp;gt; Link Selection I don't see an option to set this IP to be used as VPN peer IP for my third parties.&lt;/P&gt;&lt;P&gt;3. How this loopback interface&amp;nbsp; chooses physical interfaces to route its traffic&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Anshu Bathla&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 06:08:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-termination-on-Loopback-interfaces-R80-40/m-p/99151#M10375</guid>
      <dc:creator>ab</dc:creator>
      <dc:date>2020-10-15T06:08:46Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN termination on Loopback interfaces -R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-termination-on-Loopback-interfaces-R80-40/m-p/99156#M10376</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/31573"&gt;@ab&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;1. Is that setup feasible , Shall I give the same public IP on both the members as loopback interfaces are not a part of cluster.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;That's not possible for your needs. You have to create a dummy cluster-interface. The members are assigned private IPs and the VIP will be your public IP.&lt;/P&gt;
&lt;P&gt;With these configuration you can choose your public IP in all the needed sections in VPN link selection.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 06:38:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-termination-on-Loopback-interfaces-R80-40/m-p/99156#M10376</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-10-15T06:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN termination on Loopback interfaces -R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-termination-on-Loopback-interfaces-R80-40/m-p/99160#M10377</link>
      <description>&lt;P&gt;Thanks Wolfgang,&lt;/P&gt;&lt;P&gt;Shall I consider that&amp;nbsp;as of now terminating the IPsec VPN is not at all possible on Loopback interfaces&amp;nbsp; on Checkpoint Firewalls?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Oct 2020 07:04:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-termination-on-Loopback-interfaces-R80-40/m-p/99160#M10377</guid>
      <dc:creator>ab</dc:creator>
      <dc:date>2020-10-15T07:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN termination on Loopback interfaces -R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-termination-on-Loopback-interfaces-R80-40/m-p/99377#M10378</link>
      <description>&lt;P&gt;Just set the Link Selection IP to a static IP which does not have to be associated with a gateway interface at all.&lt;/P&gt;</description>
      <pubDate>Sun, 18 Oct 2020 05:32:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-termination-on-Loopback-interfaces-R80-40/m-p/99377#M10378</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-18T05:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN termination on Loopback interfaces -R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-termination-on-Loopback-interfaces-R80-40/m-p/100123#M10379</link>
      <description>&lt;P&gt;Hi Anshu,&lt;/P&gt;&lt;P&gt;we also have the same requirement, Were u able to make it work with the dummy cluster interface. Please share your feedback&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 08:08:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-termination-on-Loopback-interfaces-R80-40/m-p/100123#M10379</guid>
      <dc:creator>libin</dc:creator>
      <dc:date>2020-10-26T08:08:53Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN termination on Loopback interfaces -R80.40</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-termination-on-Loopback-interfaces-R80-40/m-p/257149#M50381</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;have you any feedback for this configuration? can we finalise the VPN IPSEC on a dummy INterface ?&lt;/P&gt;&lt;P&gt;What doesn't it mean exactly? should I define on GAIA System also an interface with the private IP address then define the public IP addresse on the CLuster Topologie?&lt;/P&gt;&lt;P&gt;Thank you for your reply&lt;/P&gt;</description>
      <pubDate>Fri, 12 Sep 2025 06:51:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IPsec-VPN-termination-on-Loopback-interfaces-R80-40/m-p/257149#M50381</guid>
      <dc:creator>laurent_ragon</dc:creator>
      <dc:date>2025-09-12T06:51:05Z</dc:date>
    </item>
  </channel>
</rss>

