<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to site VPN with different local ip in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-with-different-local-ip/m-p/123458#M17736</link>
    <description>&lt;P&gt;Any change to the Link Selection settings will impact all configured VPNs.&lt;BR /&gt;The only way you can have a different IP is to route the traffic out a different physical interface.&lt;BR /&gt;This precludes the use of an interface alias or proxy arp.&lt;BR /&gt;Not sure we support having multiple physical interfaces on the same subnet.&lt;/P&gt;
&lt;P&gt;One way I know will work is to use VSX (having each VPN terminate on a different VS).&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 10 Jul 2021 00:07:18 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-07-10T00:07:18Z</dc:date>
    <item>
      <title>Site to site VPN with different local ip</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-with-different-local-ip/m-p/123399#M17699</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;We have a problem with setting up Site to site VPN for a checkpoint.&lt;BR /&gt;The problem is that the provider gave us a range of IP addresses, and we want to set up VPN with different organizations using our different public IP addresses&lt;/P&gt;&lt;P&gt;For example, we were given a range of public IP addresses 20.20.20.0/29. ip address 20.20.20.1/24 is registered on the provider's gateway, ip 20.20.20.2 is registered on the physical interface of our checkpoint. This is the checkpoint gateway. We have 4 IP addresses in stock, these are 20.20.20.3, 20.20.20.4, 20.20.20.5, 20.20.20.6.&lt;BR /&gt;Site to site VPN at our address 20.20.20.2 is already configured with organization1&lt;BR /&gt;We need to create another Site to site VPN and use the IP address 20.20.20.3 to communicate via VPN with organization 2.&lt;/P&gt;&lt;P&gt;When creating a VPN community as our side, we can select only the address of our gateway, which is registered on the physical interface, this is 20.20.20.2, how can we choose the address 20.20.20.3&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 04:15:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-with-different-local-ip/m-p/123399#M17699</guid>
      <dc:creator>nastiakhon</dc:creator>
      <dc:date>2021-07-09T04:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN with different local ip</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-with-different-local-ip/m-p/123400#M17700</link>
      <description>&lt;P&gt;The way to change the IP used for Site-To-Site VPN is the Link Selection setting in the gateway object.&lt;BR /&gt;Unfortunately you cannot directly specify it per-peer, but you can influence it based on routing out a different interface for different addresses.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 05:45:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-with-different-local-ip/m-p/123400#M17700</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-09T05:45:52Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN with different local ip</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-with-different-local-ip/m-p/123407#M17703</link>
      <description>&lt;P&gt;Thanks for the answer,&lt;BR /&gt;It turns out that my VPN, which is already configured, will I need to destroy it? and change the settings on all sides on all VPNs, both on my side and on the remote.&lt;BR /&gt;If I specify a new / different IP address in the Link Selection setting in the gateway object, then it will be applied to all my Site-To-Site VPNs.&lt;BR /&gt;There may be some alternative way to use different public IP addresses for different Site-To-Site VPNs (from the same subnet from the provider). Maybe I can do this with the help of an alias? Register an alias on the physical interface, and then specify this IP alias in the VPN community like that?&lt;/P&gt;&lt;P&gt;Maybe somehow you can do it with the help of proxy ARP?&lt;BR /&gt;Can you please tell me if there is such a possibility?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 08:29:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-with-different-local-ip/m-p/123407#M17703</guid>
      <dc:creator>nastiakhon</dc:creator>
      <dc:date>2021-07-09T08:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN with different local ip</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-with-different-local-ip/m-p/123458#M17736</link>
      <description>&lt;P&gt;Any change to the Link Selection settings will impact all configured VPNs.&lt;BR /&gt;The only way you can have a different IP is to route the traffic out a different physical interface.&lt;BR /&gt;This precludes the use of an interface alias or proxy arp.&lt;BR /&gt;Not sure we support having multiple physical interfaces on the same subnet.&lt;/P&gt;
&lt;P&gt;One way I know will work is to use VSX (having each VPN terminate on a different VS).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jul 2021 00:07:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-with-different-local-ip/m-p/123458#M17736</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-10T00:07:18Z</dc:date>
    </item>
  </channel>
</rss>

