<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Site-to-Site ISB Migration Question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-ISB-Migration-Question/m-p/120923#M17184</link>
    <description>&lt;P&gt;Hey Mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are running 80.20 in our headquarter and use 1430 Appliances in our branch offices.&lt;/P&gt;&lt;P&gt;Currently we are facing perfomance issues and it seems the internet connection we use for the site-to-site vpns might be undersized.&lt;/P&gt;&lt;P&gt;We have 2 ISPs and so far we are using only one for the site-to-site. The second line is bigger and we would like to switch our site-to-sites to the bigger connection.&lt;/P&gt;&lt;P&gt;However, we would like to test it with our lab and we are currently lost on how to do this.&lt;/P&gt;&lt;P&gt;Our firewall cluster is in an Encryption Domain with "always use this addess" configuration to public IP adress of the weak line. We looked at link selection but we are uncertain if that is the solution to our problem&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;Each interface is used by a different remote party:&lt;/SPAN&gt;&lt;SPAN&gt;The local Security Gateway has two IP addresses used for VPN. One interface is used for VPN with &lt;/SPAN&gt;&lt;SPAN&gt;a peer Security Gateway A and one interface for peer Security Gateway B.&lt;/SPAN&gt;&lt;SPAN&gt;To determine how peer Security Gateways discover the IP address of the local Security Gateway, &lt;/SPAN&gt;&lt;SPAN&gt;enable &lt;/SPAN&gt;&lt;SPAN&gt;one&lt;/SPAN&gt;&lt;SPAN&gt;-time probing&lt;/SPAN&gt;&lt;SPAN&gt; with &lt;/SPAN&gt;&lt;SPAN&gt;High Availability&lt;/SPAN&gt;&lt;SPAN&gt; redundancy mode. Since only one IP is available &lt;/SPAN&gt;&lt;SPAN&gt;for each peer Security Gateway, probing only has to take place one time.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Would this work for us? We want the test site-to-site to strictly use one IP to test the connection. From what I gather from the documentation link selection is more for high availability and less for strict traffic separation.&lt;/P&gt;&lt;P&gt;Any tips would be appreciated&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Jun 2021 08:45:42 GMT</pubDate>
    <dc:creator>Alias</dc:creator>
    <dc:date>2021-06-11T08:45:42Z</dc:date>
    <item>
      <title>Site-to-Site ISB Migration Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-ISB-Migration-Question/m-p/120923#M17184</link>
      <description>&lt;P&gt;Hey Mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are running 80.20 in our headquarter and use 1430 Appliances in our branch offices.&lt;/P&gt;&lt;P&gt;Currently we are facing perfomance issues and it seems the internet connection we use for the site-to-site vpns might be undersized.&lt;/P&gt;&lt;P&gt;We have 2 ISPs and so far we are using only one for the site-to-site. The second line is bigger and we would like to switch our site-to-sites to the bigger connection.&lt;/P&gt;&lt;P&gt;However, we would like to test it with our lab and we are currently lost on how to do this.&lt;/P&gt;&lt;P&gt;Our firewall cluster is in an Encryption Domain with "always use this addess" configuration to public IP adress of the weak line. We looked at link selection but we are uncertain if that is the solution to our problem&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;SPAN&gt;Each interface is used by a different remote party:&lt;/SPAN&gt;&lt;SPAN&gt;The local Security Gateway has two IP addresses used for VPN. One interface is used for VPN with &lt;/SPAN&gt;&lt;SPAN&gt;a peer Security Gateway A and one interface for peer Security Gateway B.&lt;/SPAN&gt;&lt;SPAN&gt;To determine how peer Security Gateways discover the IP address of the local Security Gateway, &lt;/SPAN&gt;&lt;SPAN&gt;enable &lt;/SPAN&gt;&lt;SPAN&gt;one&lt;/SPAN&gt;&lt;SPAN&gt;-time probing&lt;/SPAN&gt;&lt;SPAN&gt; with &lt;/SPAN&gt;&lt;SPAN&gt;High Availability&lt;/SPAN&gt;&lt;SPAN&gt; redundancy mode. Since only one IP is available &lt;/SPAN&gt;&lt;SPAN&gt;for each peer Security Gateway, probing only has to take place one time.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Would this work for us? We want the test site-to-site to strictly use one IP to test the connection. From what I gather from the documentation link selection is more for high availability and less for strict traffic separation.&lt;/P&gt;&lt;P&gt;Any tips would be appreciated&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Jun 2021 08:45:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-ISB-Migration-Question/m-p/120923#M17184</guid>
      <dc:creator>Alias</dc:creator>
      <dc:date>2021-06-11T08:45:42Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site ISB Migration Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-ISB-Migration-Question/m-p/121084#M17215</link>
      <description>&lt;P&gt;Changing the Link Selection settings is the correct approach here.&lt;BR /&gt;If you want the VPN to use the other ISP, you would specify that IP in the Link Selection settings either directly by IP or indirectly by using one of the other options (routing, etc).&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 03:34:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-ISB-Migration-Question/m-p/121084#M17215</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-14T03:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Site-to-Site ISB Migration Question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-ISB-Migration-Question/m-p/121335#M17259</link>
      <description>&lt;P&gt;Thank you, I will try&lt;/P&gt;</description>
      <pubDate>Wed, 16 Jun 2021 09:28:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-Site-ISB-Migration-Question/m-p/121335#M17259</guid>
      <dc:creator>Alias</dc:creator>
      <dc:date>2021-06-16T09:28:20Z</dc:date>
    </item>
  </channel>
</rss>

