<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change current critical production VPN configuration change &amp;gt; Link selection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160587#M28329</link>
    <description>&lt;P&gt;If you have multiple external interfaces and uplinks and need 3rd party VPN to work with different uplinks (pre-shared key), then you need&amp;nbsp;&lt;SPAN&gt;sk173048:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk173048&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk173048&amp;amp;partition=Advanced&amp;amp;product=IPSec&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In Link Selection, the first option can remain at "Main Address". &amp;nbsp;For Outgoing link, choose "based on routing decision". For "When responding..." option, choose "reply from same interface".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;On the gateways, set static route to the external gateway out whichever interface link.&lt;/P&gt;
&lt;P&gt;Setting this registry does require a cpstop;cpstart. &amp;nbsp;You can do it on one cluster member at a time, however, with no outage.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Oct 2022 14:03:44 GMT</pubDate>
    <dc:creator>Duane_Toler</dc:creator>
    <dc:date>2022-10-27T14:03:44Z</dc:date>
    <item>
      <title>Change current critical production VPN configuration change &gt; Link selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160201#M28216</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need clear understanding to change live critical VPN configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My requirement is we have 28 Live VPNs on Checkpoint Gateway. with one ISP provider. link selection we have configured checkpoint cluster-related VIP on link selection in a select address on the topology table option.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now we have a new requirement we have to create a new VPN tunnel using another ISP link (NEW), based on our configuration this will not work because the link will select based on our previous configuration (Link selection).&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Does anyone have a clear idea of how can we change this without major downtimes?&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. How technically work " Calculate IP Based on network topology" in link selection options, do we need to enable ISP redundancy for this requirement?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Duminda Lakmal.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Oct 2022 04:28:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160201#M28216</guid>
      <dc:creator>Duminda_lakmal</dc:creator>
      <dc:date>2022-10-24T04:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: Change current critical production VPN configuration change &gt; Link selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160433#M28269</link>
      <description>&lt;P&gt;An answer depends on many things. One VPN community or multiple? Can you have two ISP links up at the same time? Those 28 remote GWs, who is managing them?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 09:48:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160433#M28269</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-26T09:48:40Z</dc:date>
    </item>
    <item>
      <title>Re: Change current critical production VPN configuration change &gt; Link selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160486#M28281</link>
      <description>&lt;P&gt;ISP Redundancy is only needed if you are changing the default route for ALL traffic.&lt;BR /&gt;If you're just routing traffic for a specific VPN out a specific interface to go out a different ISP, all that's really needed is static routes on the gateway for the relevant VPN subnets to point to the nexthop IP of the other ISP.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 16:15:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160486#M28281</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-26T16:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: Change current critical production VPN configuration change &gt; Link selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160487#M28282</link>
      <description>&lt;P&gt;Keep in mind that even if you are using ISP redundancy, if one link fails, VPN tunnels will never get reestablished, as other end will never know about "new" external IP address.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topics-FWG/ISP-Redundancy-and-VPN.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_NextGenSecurityGateway_Guide/Topics-FWG/ISP-Redundancy-and-VPN.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Though based on what it says on top of that link, its not 100% clear, maybe someone else can confirm:&lt;/P&gt;
&lt;TABLE class="TableStyle-TP_Table_Notes" cellspacing="0"&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Notes-Body-Body"&gt;
&lt;TD class="TableStyle-TP_Table_Notes-BodyA-Column_Style_Text-Body"&gt;
&lt;P&gt;&lt;SPAN class="Note"&gt;Note&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ispr variable"&gt;ISP Redundancy&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;settings override the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;VPN Link Selection&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;settings.&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;When&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ispr variable"&gt;ISP Redundancy&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is enabled, VPN encrypted connections survive a failure of an ISP link.&lt;/P&gt;
&lt;P&gt;The settings in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ispr variable"&gt;ISP Redundancy&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;page override settings in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ipsecvpn variable"&gt;IPsec VPN&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt; Link Selection&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;page&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 17:30:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160487#M28282</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-26T17:30:08Z</dc:date>
    </item>
    <item>
      <title>Re: Change current critical production VPN configuration change &gt; Link selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160520#M28312</link>
      <description>&lt;P&gt;Hi Val, currently we have 28 communities, but we are not touching those communities. those will be running with an existing WAN link, without any changes, those remote peers not manage us.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a new ISP link it was not connected to the checkpoint yet. once this link configuration is clarified we are planning to lay cables and configurations. and we need to create a new VPN community by connecting mentioned new ISP WAN connection.&amp;nbsp;&lt;/P&gt;&lt;P&gt;what will happen if we are creating a static route to mentioned new Peer GW through mentioned NEW IPS link (our default route will still remain and not impact current connections). and set the gateway configuration, &amp;gt; link selection &amp;gt; set -&amp;nbsp;&lt;SPAN&gt;Calculate IP Based on network topology. what are the impact when we do this? kindly help me, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I cannot find the guide for like these configurations.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Duminda Lakmal&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 04:29:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160520#M28312</guid>
      <dc:creator>Duminda_lakmal</dc:creator>
      <dc:date>2022-10-27T04:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: Change current critical production VPN configuration change &gt; Link selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160521#M28313</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much for the advice. kindly advise what happen we set the:&amp;nbsp;&lt;SPAN&gt;gateway configuration, &amp;gt; link selection &amp;gt; set -&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Calculate IP Based on network topology options with static routes?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 04:32:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160521#M28313</guid>
      <dc:creator>Duminda_lakmal</dc:creator>
      <dc:date>2022-10-27T04:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Change current critical production VPN configuration change &gt; Link selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160587#M28329</link>
      <description>&lt;P&gt;If you have multiple external interfaces and uplinks and need 3rd party VPN to work with different uplinks (pre-shared key), then you need&amp;nbsp;&lt;SPAN&gt;sk173048:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk173048&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk173048&amp;amp;partition=Advanced&amp;amp;product=IPSec&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In Link Selection, the first option can remain at "Main Address". &amp;nbsp;For Outgoing link, choose "based on routing decision". For "When responding..." option, choose "reply from same interface".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;On the gateways, set static route to the external gateway out whichever interface link.&lt;/P&gt;
&lt;P&gt;Setting this registry does require a cpstop;cpstart. &amp;nbsp;You can do it on one cluster member at a time, however, with no outage.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Oct 2022 14:03:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Change-current-critical-production-VPN-configuration-change-gt/m-p/160587#M28329</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2022-10-27T14:03:44Z</dc:date>
    </item>
  </channel>
</rss>

