<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to site VPN using backup ISP for one site in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159962#M28149</link>
    <description>&lt;P&gt;Ok, I am running installs of the latest &lt;SPAN&gt;Check_Point_R81_10_JUMBO_HF_MAIN_Bundle_T78 right now on the clusters so that restarts during the install.&amp;nbsp; I will see if that resolves it.&amp;nbsp; If not we can get a case rolling.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2022 13:28:53 GMT</pubDate>
    <dc:creator>Luke_Abrams</dc:creator>
    <dc:date>2022-10-19T13:28:53Z</dc:date>
    <item>
      <title>Site to site VPN using backup ISP for one site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159741#M28139</link>
      <description>&lt;P&gt;Hello we have 4 sites total, 3 remote sites that connect back to our primary site via site to site vpn tunnels.&amp;nbsp; All sites are checkpoint.&amp;nbsp; One of our sites has a hop that is dropping/losing/whatever with packets and this is causing major slowness.&amp;nbsp; Our primary ISP isn't being helpful since it isn't on their network.&amp;nbsp; During our testing we found that if we use our backup ISP, it will use a different path and the slowness is gone.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So all of that to ask is it possible to route 1 site to site vpn over the backup ISP while leaving the others routed over the primary ISP?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 15:14:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159741#M28139</guid>
      <dc:creator>Luke_Abrams</dc:creator>
      <dc:date>2022-10-17T15:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN using backup ISP for one site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159755#M28140</link>
      <description>&lt;P&gt;Yes, you will need to adjust the Link Selection setting to make decision based on the routing table.&lt;BR /&gt;Refer to:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SitetoSiteVPN_AdminGuide/Topics-VPNSG/Link-Selection.htm?tocpath=Link%20Selection%7C_____0#Link_Selection" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SitetoSiteVPN_AdminGuide/Topics-VPNSG/Link-Selection.htm?tocpath=Link%20Selection%7C_____0#Link_Selection&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2022 18:46:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159755#M28140</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-17T18:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN using backup ISP for one site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159882#M28141</link>
      <description>&lt;P&gt;I am looking through the article you provided, my scenario from the way I see it would be similar to "Security Gateway with Several IP Addresses Used by Different Parties"&amp;nbsp; There doesn't seem to be much direction on that one though. All sites have static addresses.&amp;nbsp; I only want the one site to run on the alternate ISP.&amp;nbsp; So I would need to add some routing on the local gateways to accomplish this?&amp;nbsp; I am not sure if it make a difference or not but the remote site is running SMB's 1600 series.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 19:01:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159882#M28141</guid>
      <dc:creator>Luke_Abrams</dc:creator>
      <dc:date>2022-10-18T19:01:55Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN using backup ISP for one site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159883#M28142</link>
      <description>&lt;P&gt;Yes, you would route all traffic for that particular site through the other ISP using static routes.&lt;BR /&gt;This will cause Link Selection to use the appropriate interface IP when doing a Site to Site VPN on that interface.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 19:14:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159883#M28142</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-18T19:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN using backup ISP for one site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159886#M28143</link>
      <description>&lt;P&gt;Would those static routes be on the remote site pointing back at the main site or at the main site pointing at the remote site?&amp;nbsp; Or would it be on both?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 19:28:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159886#M28143</guid>
      <dc:creator>Luke_Abrams</dc:creator>
      <dc:date>2022-10-18T19:28:09Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN using backup ISP for one site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159887#M28144</link>
      <description>&lt;P&gt;The routes would be on the gateway where Link Selection is configured.&lt;BR /&gt;If the remote site has multiple ISPs also, you might want routes configured there as well to ensure symmetry.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 19:38:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159887#M28144</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-18T19:38:49Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN using backup ISP for one site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159892#M28145</link>
      <description>&lt;P&gt;I guess I am missing something sorry - So often pictures are worth a 1000 words so I will include some pics below.&amp;nbsp; First is the the link selection configuration from the Primary site - 71 is the normal ISP link 122 is the one I want this connection only to go out of.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PrimarySiteLinkSelection.png" style="width: 761px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18161iC19470031D9FD937/image-size/large?v=v2&amp;amp;px=999" role="button" title="PrimarySiteLinkSelection.png" alt="PrimarySiteLinkSelection.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The second picture is of the static routes configured for this.&amp;nbsp; The 91-93 are the external addresses of the remote cluster, Eth3 is the external interface of the alternate ISP I want this remote site to connect on.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PrimarySiteRouting.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18162i438E98888FF9DAC4/image-size/large?v=v2&amp;amp;px=999" role="button" title="PrimarySiteRouting.png" alt="PrimarySiteRouting.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However my tunnel still is connecting on the 71 ISP even after resetting it multiple times.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 20:11:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159892#M28145</guid>
      <dc:creator>Luke_Abrams</dc:creator>
      <dc:date>2022-10-18T20:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN using backup ISP for one site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159898#M28146</link>
      <description>&lt;P&gt;You're using an interface route when you should be using an IP-based nexthop (specifically to the default route for ISP2).&lt;BR /&gt;Also, what is the Source IP address setting say?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 22:26:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159898#M28146</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-18T22:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN using backup ISP for one site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159958#M28147</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;So it should work like this?&amp;nbsp; It looks like it is still using the gateway of .65 even after tunnel resets.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PrimarySiteRouting2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18170i952483A28ED6FC45/image-size/large?v=v2&amp;amp;px=999" role="button" title="PrimarySiteRouting2.png" alt="PrimarySiteRouting2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PrimarySiteSourceSetting.png" style="width: 419px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18171i4F9DACEBC700694E/image-size/large?v=v2&amp;amp;px=999" role="button" title="PrimarySiteSourceSetting.png" alt="PrimarySiteSourceSetting.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PrimarySiteTunnels.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18172i6326C6A2B98330D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="PrimarySiteTunnels.png" alt="PrimarySiteTunnels.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 13:24:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159958#M28147</guid>
      <dc:creator>Luke_Abrams</dc:creator>
      <dc:date>2022-10-19T13:24:34Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN using backup ISP for one site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159961#M28148</link>
      <description>&lt;P&gt;Yes like that.&lt;BR /&gt;And, unless a reboot solves it, I recommend a TAC case for further troubleshooting.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 13:25:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159961#M28148</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-19T13:25:10Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN using backup ISP for one site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159962#M28149</link>
      <description>&lt;P&gt;Ok, I am running installs of the latest &lt;SPAN&gt;Check_Point_R81_10_JUMBO_HF_MAIN_Bundle_T78 right now on the clusters so that restarts during the install.&amp;nbsp; I will see if that resolves it.&amp;nbsp; If not we can get a case rolling.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 13:28:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159962#M28149</guid>
      <dc:creator>Luke_Abrams</dc:creator>
      <dc:date>2022-10-19T13:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN using backup ISP for one site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159980#M28152</link>
      <description>&lt;P&gt;Our SMB at the remote site is managed by the same manager as the main site and the main site IP has its external set as its main IP.&amp;nbsp; Does this change anything on what we need to configure?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 15:37:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159980#M28152</guid>
      <dc:creator>Luke_Abrams</dc:creator>
      <dc:date>2022-10-19T15:37:48Z</dc:date>
    </item>
    <item>
      <title>Re: Site to site VPN using backup ISP for one site</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159983#M28153</link>
      <description>&lt;P&gt;You shouldn't need to.&lt;BR /&gt;That said, I highly recommend having TAC review your configuration.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 15:52:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Site-to-site-VPN-using-backup-ISP-for-one-site/m-p/159983#M28153</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-19T15:52:33Z</dc:date>
    </item>
  </channel>
</rss>

