<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point AWS Direct Connectivity BGP ECMP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-AWS-Direct-Connectivity-BGP-ECMP/m-p/154234#M26099</link>
    <description>&lt;P&gt;Yeah - Thanks for the response. So I hope I dont need to disable best-path selection policy of something. Just like in my other router setup I had to relax best path selection. In case of Check Point if all the attributes match and have ecmp enable I should see multiple paths added in route table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 31 Jul 2022 07:23:38 GMT</pubDate>
    <dc:creator>Blason_R</dc:creator>
    <dc:date>2022-07-31T07:23:38Z</dc:date>
    <item>
      <title>Check Point AWS Direct Connectivity BGP ECMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-AWS-Direct-Connectivity-BGP-ECMP/m-p/154211#M26084</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;I have been asked to deploy 4 links to AWS DX connectivity. This is over BGP and I wanted to enable BGP ECMP so that all those links will be utilized. However I wanted to confirm if the traffic leaves from LAN to AWS will be delivered from the same link and if not will firewall accept the connection if receives from other link since its gonna be asynchronous routing.&lt;/P&gt;&lt;P&gt;Here is diagram - &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AWS-Direct Connect Terminatev1.0.13082021.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17345i0405D772A56227F8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AWS-Direct Connect Terminatev1.0.13082021.jpg" alt="AWS-Direct Connect Terminatev1.0.13082021.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any specific considerations?&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2022 03:43:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-AWS-Direct-Connectivity-BGP-ECMP/m-p/154211#M26084</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-07-30T03:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point AWS Direct Connectivity BGP ECMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-AWS-Direct-Connectivity-BGP-ECMP/m-p/154212#M26085</link>
      <description>&lt;P&gt;As is so long as anti-spoofing is configured correctly to permit traffic on the available paths and the same Firewall see both sides of the flow this shouldn't be a problem.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more information on BGP ECMP and the consideration for the configuration please see&amp;nbsp;&lt;SPAN&gt;sk100504.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jul 2022 04:23:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-AWS-Direct-Connectivity-BGP-ECMP/m-p/154212#M26085</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-30T04:23:27Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point AWS Direct Connectivity BGP ECMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-AWS-Direct-Connectivity-BGP-ECMP/m-p/154234#M26099</link>
      <description>&lt;P&gt;Yeah - Thanks for the response. So I hope I dont need to disable best-path selection policy of something. Just like in my other router setup I had to relax best path selection. In case of Check Point if all the attributes match and have ecmp enable I should see multiple paths added in route table.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2022 07:23:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-AWS-Direct-Connectivity-BGP-ECMP/m-p/154234#M26099</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-07-31T07:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point AWS Direct Connectivity BGP ECMP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-AWS-Direct-Connectivity-BGP-ECMP/m-p/154235#M26100</link>
      <description>&lt;P&gt;To an extent that's what route-maps are for to adjust local_pref or &lt;A href="https://community.checkpoint.com/t5/Security-Gateways/AS-Path-prepending-to-two-different-peers-in-the-same-AS/td-p/132851" target="_self"&gt;as-path pre-pending&lt;/A&gt; to make the paths seem equal when attributes aren't necessarily as you need them.&lt;/P&gt;</description>
      <pubDate>Sun, 31 Jul 2022 08:37:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-AWS-Direct-Connectivity-BGP-ECMP/m-p/154235#M26100</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-31T08:37:58Z</dc:date>
    </item>
  </channel>
</rss>

