<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Redundant VPN Connection using ISP L2 connection and S2S VPN in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Redundant-VPN-Connection-using-ISP-L2-connection-and-S2S-VPN/m-p/113672#M15865</link>
    <description>&lt;P&gt;Dear mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, I have a VPN setup between 2 locations wherein Primary premises I have a cluster and at DR a single GW.&lt;/P&gt;&lt;P&gt;We are using a Site to Site VPN and now we need to add a 2nd L2 line connection as primary and keep the Site-to-Site as a secondary.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The GWs now, are connected with each end of L2 line and between there is also one switch. (GW -&amp;gt; switch -&amp;gt; end of L2 connection -&amp;gt; end of DR L2 connection -&amp;gt;GW)&lt;/P&gt;&lt;P&gt;Here are the steps we try so far:&lt;/P&gt;&lt;P&gt;1. Create a new VLAN for the L2 connection.&lt;BR /&gt;2. Assign the new VLAN’s IPs to the GWs and the switch interface.&lt;/P&gt;&lt;P&gt;3. Create new IP routes on both GWs to redirect traffic to pass from L2 Connection. -&amp;gt; Failed to work.&lt;/P&gt;&lt;P&gt;5. Create 2 new GWs as Interoperable Device and modify Site to Site VPN using new GWs object with internal L2 IPs. -&amp;gt; Failed to work.&lt;/P&gt;&lt;P&gt;6.Remove IP routes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The plan is to keep the Site to Site VPN and also pass the traffic through the L2 connection encrypted.&lt;/P&gt;&lt;P&gt;Regarding link redundancy mode, please note that we have also other remote locations and I think I can't use it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Mar 2021 13:46:21 GMT</pubDate>
    <dc:creator>SdanteMate</dc:creator>
    <dc:date>2021-03-16T13:46:21Z</dc:date>
    <item>
      <title>Redundant VPN Connection using ISP L2 connection and S2S VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Redundant-VPN-Connection-using-ISP-L2-connection-and-S2S-VPN/m-p/113672#M15865</link>
      <description>&lt;P&gt;Dear mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently, I have a VPN setup between 2 locations wherein Primary premises I have a cluster and at DR a single GW.&lt;/P&gt;&lt;P&gt;We are using a Site to Site VPN and now we need to add a 2nd L2 line connection as primary and keep the Site-to-Site as a secondary.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The GWs now, are connected with each end of L2 line and between there is also one switch. (GW -&amp;gt; switch -&amp;gt; end of L2 connection -&amp;gt; end of DR L2 connection -&amp;gt;GW)&lt;/P&gt;&lt;P&gt;Here are the steps we try so far:&lt;/P&gt;&lt;P&gt;1. Create a new VLAN for the L2 connection.&lt;BR /&gt;2. Assign the new VLAN’s IPs to the GWs and the switch interface.&lt;/P&gt;&lt;P&gt;3. Create new IP routes on both GWs to redirect traffic to pass from L2 Connection. -&amp;gt; Failed to work.&lt;/P&gt;&lt;P&gt;5. Create 2 new GWs as Interoperable Device and modify Site to Site VPN using new GWs object with internal L2 IPs. -&amp;gt; Failed to work.&lt;/P&gt;&lt;P&gt;6.Remove IP routes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The plan is to keep the Site to Site VPN and also pass the traffic through the L2 connection encrypted.&lt;/P&gt;&lt;P&gt;Regarding link redundancy mode, please note that we have also other remote locations and I think I can't use it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Mar 2021 13:46:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Redundant-VPN-Connection-using-ISP-L2-connection-and-S2S-VPN/m-p/113672#M15865</guid>
      <dc:creator>SdanteMate</dc:creator>
      <dc:date>2021-03-16T13:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: Redundant VPN Connection using ISP L2 connection and S2S VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Redundant-VPN-Connection-using-ISP-L2-connection-and-S2S-VPN/m-p/113952#M15909</link>
      <description>&lt;P&gt;Did you change the Link Selection settings at all?&lt;BR /&gt;This is required if you're going to change the IP used for the VPN.&lt;BR /&gt;Also, are you still encrypting IPsec on the L2 connection?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 15:14:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Redundant-VPN-Connection-using-ISP-L2-connection-and-S2S-VPN/m-p/113952#M15909</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-18T15:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Redundant VPN Connection using ISP L2 connection and S2S VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Redundant-VPN-Connection-using-ISP-L2-connection-and-S2S-VPN/m-p/114067#M15924</link>
      <description>&lt;P&gt;Many thank for the response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I didn't change the Link Selection settings as I have many locations connected with HQ and I need to change only one of them.&lt;/P&gt;&lt;P&gt;Currently, the Link Section is at the Main address. If we ignore the redundant connection. There is a way just to replace the Site to Site VPN and configure a new one with privates IPs on L2 connection?&lt;/P&gt;&lt;P&gt;No, the ISP doesn't encrypt the L2 connection.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 09:44:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Redundant-VPN-Connection-using-ISP-L2-connection-and-S2S-VPN/m-p/114067#M15924</guid>
      <dc:creator>SdanteMate</dc:creator>
      <dc:date>2021-03-19T09:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: Redundant VPN Connection using ISP L2 connection and S2S VPN</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Redundant-VPN-Connection-using-ISP-L2-connection-and-S2S-VPN/m-p/114133#M15944</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Maybe try to use "Calculate IP based on network Topology."&lt;BR /&gt;As long as you have more specific routes for that VPN over L2, I believe it will choose the correct IP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Mar 2021 06:50:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Redundant-VPN-Connection-using-ISP-L2-connection-and-S2S-VPN/m-p/114133#M15944</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-20T06:50:45Z</dc:date>
    </item>
  </channel>
</rss>

