<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Third party IPSEC VPN with 2 peers in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Third-party-IPSEC-VPN-with-2-peers/m-p/115749#M16309</link>
    <description>&lt;P&gt;I agree, but it would also be nice if Checkpoint accounted for scenario in the community ie. maybe by a priority list or recognise a back device in the community.&lt;/P&gt;</description>
    <pubDate>Sat, 10 Apr 2021 14:17:19 GMT</pubDate>
    <dc:creator>genisis__</dc:creator>
    <dc:date>2021-04-10T14:17:19Z</dc:date>
    <item>
      <title>Third party IPSEC VPN with 2 peers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Third-party-IPSEC-VPN-with-2-peers/m-p/115428#M16227</link>
      <description>&lt;P&gt;Hello all, sorry if this is already answered before, I've searched here and couldn't find anything related.&lt;/P&gt;&lt;P&gt;We have a customer that we need to establish an "HA" IPSEC VPN, they have 2 remote peer addresses, let's name them site A and site B, both using Cisco ASA, being site A the peferable one, if it becomes unavailable, we would still have VPN established with site B.&lt;/P&gt;&lt;P&gt;I have a local R80.40 GW. I know I can set a VPN community and add both interoperable devices to it, but how can I be sure that the traffic would only go to site B if site A is unavailable?&lt;/P&gt;&lt;P&gt;I also know that I could create 2 vpn communities, but if I do that I think I would have problem with the encryption domain because they would be the same, right?&lt;/P&gt;&lt;P&gt;What would be the best way to achieve this setup?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 20:18:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Third-party-IPSEC-VPN-with-2-peers/m-p/115428#M16227</guid>
      <dc:creator>hugothebas</dc:creator>
      <dc:date>2021-04-06T20:18:31Z</dc:date>
    </item>
    <item>
      <title>Re: Third party IPSEC VPN with 2 peers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Third-party-IPSEC-VPN-with-2-peers/m-p/115430#M16228</link>
      <description>&lt;P&gt;I think the simplest and most predictable way to control this would be a route-based VPN with dynamic routing. Route-based VPNs involve setting up a virtual interface (called a VTI) on your firewall which acts like a really long Ethernet cable going to the remote VPN endpoint. Since it's an interface, you can do most of the normal interface things like running OSPF or BGP on it. Once you have dynamic routing set up, the other side can control which path you prefer by tweaking router IDs, OSPF link cost, or any number of other properties.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 20:35:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Third-party-IPSEC-VPN-with-2-peers/m-p/115430#M16228</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-04-06T20:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Third party IPSEC VPN with 2 peers</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Third-party-IPSEC-VPN-with-2-peers/m-p/115749#M16309</link>
      <description>&lt;P&gt;I agree, but it would also be nice if Checkpoint accounted for scenario in the community ie. maybe by a priority list or recognise a back device in the community.&lt;/P&gt;</description>
      <pubDate>Sat, 10 Apr 2021 14:17:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Third-party-IPSEC-VPN-with-2-peers/m-p/115749#M16309</guid>
      <dc:creator>genisis__</dc:creator>
      <dc:date>2021-04-10T14:17:19Z</dc:date>
    </item>
  </channel>
</rss>

