<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN tunnel redundancy on CP and also on ASA-peer. Any way to achieve dual VPN on both sides? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-redundancy-on-CP-and-also-on-ASA-peer-Any-way-to/m-p/133084#M19776</link>
    <description>&lt;P&gt;CP Checkmates,!&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;BR /&gt;The setup we have in place for SITE to SITE VPN:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Star community has 2 CP Clusters defined and 1 ASA object under satellite. MEP has enabled hence the failover works fine should one of the CPs become unresponsive.&lt;BR /&gt;&lt;BR /&gt;SMS/Gateways are at R80.30.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Requirement:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;We need to add redundancy on the peer side as well. (Basically, one more peer needs to be added along with ASA-Main, which would be ASA-DR.)&lt;/P&gt;&lt;P&gt;&lt;U&gt;Problem:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;When we add ASA-DR, along with ASA-Main, both tunnels come up and cause an outage.&lt;BR /&gt;For now, we have removed the ASA-DR to keep the setup in a working state.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am looking for any possible solutions, please.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;YM&lt;/P&gt;</description>
    <pubDate>Tue, 02 Nov 2021 20:22:52 GMT</pubDate>
    <dc:creator>YuvrajMe147</dc:creator>
    <dc:date>2021-11-02T20:22:52Z</dc:date>
    <item>
      <title>VPN tunnel redundancy on CP and also on ASA-peer. Any way to achieve dual VPN on both sides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-redundancy-on-CP-and-also-on-ASA-peer-Any-way-to/m-p/133084#M19776</link>
      <description>&lt;P&gt;CP Checkmates,!&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;BR /&gt;The setup we have in place for SITE to SITE VPN:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;Star community has 2 CP Clusters defined and 1 ASA object under satellite. MEP has enabled hence the failover works fine should one of the CPs become unresponsive.&lt;BR /&gt;&lt;BR /&gt;SMS/Gateways are at R80.30.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Requirement:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;We need to add redundancy on the peer side as well. (Basically, one more peer needs to be added along with ASA-Main, which would be ASA-DR.)&lt;/P&gt;&lt;P&gt;&lt;U&gt;Problem:&lt;/U&gt;&lt;/P&gt;&lt;P&gt;When we add ASA-DR, along with ASA-Main, both tunnels come up and cause an outage.&lt;BR /&gt;For now, we have removed the ASA-DR to keep the setup in a working state.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I am looking for any possible solutions, please.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;YM&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 20:22:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-redundancy-on-CP-and-also-on-ASA-peer-Any-way-to/m-p/133084#M19776</guid>
      <dc:creator>YuvrajMe147</dc:creator>
      <dc:date>2021-11-02T20:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel redundancy on CP and also on ASA-peer. Any way to achieve dual VPN on both sides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-redundancy-on-CP-and-also-on-ASA-peer-Any-way-to/m-p/133252#M19820</link>
      <description>&lt;P&gt;Is there anyone who could shed a light on this topic?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 16:25:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-redundancy-on-CP-and-also-on-ASA-peer-Any-way-to/m-p/133252#M19820</guid>
      <dc:creator>YuvrajMe147</dc:creator>
      <dc:date>2021-11-04T16:25:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN tunnel redundancy on CP and also on ASA-peer. Any way to achieve dual VPN on both sides?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-redundancy-on-CP-and-also-on-ASA-peer-Any-way-to/m-p/133278#M19822</link>
      <description>&lt;P&gt;I’m not 100% on if this would work but am chiming in since there aren’t any responses yet.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;In my head it seems like a route based VPN could work for this setup.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I would imagine you could set priorities on the routes for relevant traffic to prefer the primary peer.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Nov 2021 04:11:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-tunnel-redundancy-on-CP-and-also-on-ASA-peer-Any-way-to/m-p/133278#M19822</guid>
      <dc:creator>mcatanzaro</dc:creator>
      <dc:date>2021-11-05T04:11:21Z</dc:date>
    </item>
  </channel>
</rss>

