<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Resilient VPN Data Center Solution in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Resilient-VPN-Data-Center-Solution/m-p/70166#M11835</link>
    <description>&lt;P&gt;Hi everyone, I hope you're all well. This is not so much a question, but I'd be interested to know your thoughts on best practice for a request I've been asked to work on.&lt;BR /&gt;&lt;BR /&gt;Attached is a very crude network diagram (apologies!).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have two DC's - DCR and DCS. We have a customer called Mobile City. Currently there's an IPSec VPN tunnel between Checkpoint 5800 DCR and Cisco ASA Mobile City. A lot of O365 traffic passes through this tunnel so it's rather risky not having any resilience. Hence, my request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been asked to add a second tunnel between Checkpoint 5800 DCR and Cisco ASA Mobile City, then also two brand new tunnels between Checkpoint DCS and Mobile City. It's a fairly straightforward request but I just wanted to ask whether there are any best practices when it comes to this type of request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the configuration I've been provided with by Mobile City:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Mobile City public peer IP -&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;202.154.29.17&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;DCR/DCS public peer IP -&amp;nbsp;149.133.213.4&lt;/LI&gt;&lt;LI&gt;Mobile City LAN subnet – 172.28.5.0/24&lt;/LI&gt;&lt;LI&gt;DCR/DCS LAN subnets&lt;UL&gt;&lt;LI&gt;- 10.101.0.0/16&lt;BR /&gt;- 10.102.0.0/15&lt;BR /&gt;- 10.104.0.0/16&lt;BR /&gt;- 10.128.0.0/16&lt;BR /&gt;- 10.129.0.0/16&lt;BR /&gt;- 10.130.0.0/16&lt;BR /&gt;- 10.131.0.0/16&lt;BR /&gt;- 10.132.0.0/14&lt;BR /&gt;- 10.20.0.0/16&lt;BR /&gt;- 10.20.30.0/24&lt;BR /&gt;- 10.32.0.0/13&lt;BR /&gt;- 10.41.0.0/16&lt;BR /&gt;- 10.42.0.0/16&lt;BR /&gt;- 10.43.0.0/16&lt;BR /&gt;- 10.86.0.0/15&lt;BR /&gt;- 10.88.0.0/16&lt;BR /&gt;- 10.97.0.0/16&lt;BR /&gt;- 10.98.0.0/16&lt;BR /&gt;- 172.21.0.0/16&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Crypto settings to be confirmed but IKEV2 will be used along with AES-256, DH 14 and SHA-256&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm confident I can get the tunnels up, but just wanted clarity on any further configuration on the LAN side, i.e routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What would be the best way of routing the interesting traffic, considering Mobile City has a single /24 network whereas there are a number of larger DC subnets?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, would it be wise to enable ISP redundancy for this type of solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope you can help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks in advance.&lt;/P&gt;&lt;P&gt;B&lt;/P&gt;</description>
    <pubDate>Wed, 11 Dec 2019 19:34:24 GMT</pubDate>
    <dc:creator>ziggurat</dc:creator>
    <dc:date>2019-12-11T19:34:24Z</dc:date>
    <item>
      <title>Resilient VPN Data Center Solution</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Resilient-VPN-Data-Center-Solution/m-p/70166#M11835</link>
      <description>&lt;P&gt;Hi everyone, I hope you're all well. This is not so much a question, but I'd be interested to know your thoughts on best practice for a request I've been asked to work on.&lt;BR /&gt;&lt;BR /&gt;Attached is a very crude network diagram (apologies!).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have two DC's - DCR and DCS. We have a customer called Mobile City. Currently there's an IPSec VPN tunnel between Checkpoint 5800 DCR and Cisco ASA Mobile City. A lot of O365 traffic passes through this tunnel so it's rather risky not having any resilience. Hence, my request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've been asked to add a second tunnel between Checkpoint 5800 DCR and Cisco ASA Mobile City, then also two brand new tunnels between Checkpoint DCS and Mobile City. It's a fairly straightforward request but I just wanted to ask whether there are any best practices when it comes to this type of request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the configuration I've been provided with by Mobile City:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Mobile City public peer IP -&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;202.154.29.17&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;DCR/DCS public peer IP -&amp;nbsp;149.133.213.4&lt;/LI&gt;&lt;LI&gt;Mobile City LAN subnet – 172.28.5.0/24&lt;/LI&gt;&lt;LI&gt;DCR/DCS LAN subnets&lt;UL&gt;&lt;LI&gt;- 10.101.0.0/16&lt;BR /&gt;- 10.102.0.0/15&lt;BR /&gt;- 10.104.0.0/16&lt;BR /&gt;- 10.128.0.0/16&lt;BR /&gt;- 10.129.0.0/16&lt;BR /&gt;- 10.130.0.0/16&lt;BR /&gt;- 10.131.0.0/16&lt;BR /&gt;- 10.132.0.0/14&lt;BR /&gt;- 10.20.0.0/16&lt;BR /&gt;- 10.20.30.0/24&lt;BR /&gt;- 10.32.0.0/13&lt;BR /&gt;- 10.41.0.0/16&lt;BR /&gt;- 10.42.0.0/16&lt;BR /&gt;- 10.43.0.0/16&lt;BR /&gt;- 10.86.0.0/15&lt;BR /&gt;- 10.88.0.0/16&lt;BR /&gt;- 10.97.0.0/16&lt;BR /&gt;- 10.98.0.0/16&lt;BR /&gt;- 172.21.0.0/16&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Crypto settings to be confirmed but IKEV2 will be used along with AES-256, DH 14 and SHA-256&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm confident I can get the tunnels up, but just wanted clarity on any further configuration on the LAN side, i.e routing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What would be the best way of routing the interesting traffic, considering Mobile City has a single /24 network whereas there are a number of larger DC subnets?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, would it be wise to enable ISP redundancy for this type of solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope you can help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks in advance.&lt;/P&gt;&lt;P&gt;B&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 19:34:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Resilient-VPN-Data-Center-Solution/m-p/70166#M11835</guid>
      <dc:creator>ziggurat</dc:creator>
      <dc:date>2019-12-11T19:34:24Z</dc:date>
    </item>
  </channel>
</rss>

