<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Duel Ipsec route based tunnel to Azure with BGP enabled in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/157464#M27331</link>
    <description>&lt;P&gt;The information seems to be very less.&lt;/P&gt;&lt;P&gt;How many ISPs you have on your firewall? Is this a VTI based tunnel or? Did you configure to tunnels from same ISP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 18 Sep 2022 03:59:45 GMT</pubDate>
    <dc:creator>Blason_R</dc:creator>
    <dc:date>2022-09-18T03:59:45Z</dc:date>
    <item>
      <title>Duel Ipsec route based tunnel to Azure with BGP enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/146205#M24144</link>
      <description>&lt;P&gt;Hi All ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;im looking for some document related to setup duel ipsec tunnel from check point 3200 model firewall to Azure with BGP enabled for automatic failover .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can some one share the KB or related article regarding this&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2022 13:42:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/146205#M24144</guid>
      <dc:creator>sreekanthvijay</dc:creator>
      <dc:date>2022-04-13T13:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: Duel Ipsec route based tunnel to Azure with BGP enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/146642#M24145</link>
      <description>&lt;P&gt;Did you try: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk176249&amp;amp;partition=Basic&amp;amp;product=CloudGuard" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk176249&amp;amp;partition=Basic&amp;amp;product=CloudGuard&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 23:30:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/146642#M24145</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-04-20T23:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: Duel Ipsec route based tunnel to Azure with BGP enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/157459#M27330</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;We are not using Vwan vpn gateway in azure , it is normal vpn gateway in azure and we are able to establish two tunnel with bgp to azure and we have created specific route map for traffic selection path , the problem what we are facing is when the tunnel and bgp is up and it runs with out any problem for some hour after that one of the bgp goes to active state and we need to reset the tunnel in azure side &amp;nbsp;for bgp to come up again and same thing happens for other tunnel also , so if we didn’t monitor it after certain time bgp towards azure for both vti becomes active and impact the production . In our side we have 3100 with cluster … Please suggest&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Sep 2022 14:12:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/157459#M27330</guid>
      <dc:creator>sreekanthvijay</dc:creator>
      <dc:date>2022-09-17T14:12:39Z</dc:date>
    </item>
    <item>
      <title>Re: Duel Ipsec route based tunnel to Azure with BGP enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/157464#M27331</link>
      <description>&lt;P&gt;The information seems to be very less.&lt;/P&gt;&lt;P&gt;How many ISPs you have on your firewall? Is this a VTI based tunnel or? Did you configure to tunnels from same ISP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 03:59:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/157464#M27331</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-09-18T03:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Duel Ipsec route based tunnel to Azure with BGP enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/157473#M27332</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;we have two ISP and each tunnel is established on two different ISP to azure and uses BGP between azure and check point vti&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 07:46:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/157473#M27332</guid>
      <dc:creator>sreekanthvijay</dc:creator>
      <dc:date>2022-09-18T07:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Duel Ipsec route based tunnel to Azure with BGP enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/157474#M27333</link>
      <description>&lt;P&gt;This is surprising!! You can not configure two IPsec tunnels on two ISP since Check Point will not accept. You can define VPN listening interface and then configure the tunnel. However you can define multiple tunnels from same IP to two different Azure instances and then configure BGP over IPsec.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried this multiple times since Check Point does not accept the tunnels on different interfaces hence I had to accommodate different solution and introduce router where tunnels are terminated and then configured BGP.&lt;/P&gt;&lt;P&gt;May be try running BGP traces however my gut feeling is - This is purely a IPsec issue since the peer goes into Active State in sometime.&lt;/P&gt;&lt;P&gt;What is the ouput of show bgp paths&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;show route bgp
show bgp peer &amp;lt;FIRsTPEER&amp;gt; advertise
show bgp peer &amp;lt;secondPEER&amp;gt; advertise
show bgp peer &amp;lt;FIRsTPEER&amp;gt; received
show bgp peer &amp;lt;secondPEER&amp;gt; received&lt;/LI-CODE&gt;</description>
      <pubDate>Sun, 18 Sep 2022 07:57:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/157474#M27333</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-09-18T07:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: Duel Ipsec route based tunnel to Azure with BGP enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/157494#M27341</link>
      <description>&lt;P&gt;Hi Balson ,&lt;/P&gt;&lt;P&gt;We don't have any problem for BGP advertise and received since that we have strictly controlled over the route maps and it is working as expected..&lt;/P&gt;&lt;P&gt;We have one problem is , after certain time one of the BGP peers which is going to azure is going to active state and it is not able to establish the connection until we reset the tunnel from Azure end ,&lt;/P&gt;&lt;P&gt;Flags: R - Peer restarted, W - Waiting for End-Of-RIB from Peer&lt;/P&gt;&lt;P&gt;PeerID AS Routes ActRts State InUpds OutUpds Uptime&lt;BR /&gt;&lt;BR /&gt;10.250.4.4 65522 0 0 Active 0 0 00:00:00&lt;BR /&gt;10.250.4.5 65522 9 2 Established 2 2 00:35:08&lt;/P&gt;&lt;P&gt;In the above o/p 4.4 is the secondary tunnel to Azure and 4.5 is the primary one .Do you know how we can stop this and BGP to automatically establish the connection when the SA timer expired.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Sep 2022 19:13:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/157494#M27341</guid>
      <dc:creator>sreekanthvijay</dc:creator>
      <dc:date>2022-09-18T19:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: Duel Ipsec route based tunnel to Azure with BGP enabled</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/157495#M27342</link>
      <description>&lt;P&gt;What does BGP Trace logs shows&amp;nbsp;&lt;SPAN&gt;sk101399&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2022 04:54:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duel-Ipsec-route-based-tunnel-to-Azure-with-BGP-enabled/m-p/157495#M27342</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-09-19T04:54:46Z</dc:date>
    </item>
  </channel>
</rss>

