<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN redundancy with third party devices in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166871#M30061</link>
    <description>&lt;P&gt;Reality is,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;&amp;nbsp;is 100% correct. Truth is, making this work with CP is not so easy. MEP sounds like your best bet, because without it, CP will never know how to choose the right 3rd party device in case of failure.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Jan 2023 04:24:28 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-01-06T04:24:28Z</dc:date>
    <item>
      <title>VPN redundancy with third party devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166852#M30052</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;I have found some ideas how to configure VPN redundancy with third party device (Cisco routers in my case), but some parts are not clear for me. I have one community with about ten devices (Cisco) and hub - checkpoint, everything works fine. I need to create redundancy for couple of sites, they have two ISPs. On Cisco side i am going to create two tunnels and use EMM with SLA or dynamic routing (but not sure about that, in this case i need to configure it on Checkpoint side too).&lt;/P&gt;&lt;P&gt;CheckPoint side, bunch of questions...&amp;nbsp; Looks like i have to create more Interoperable devices and add them to Community, but in this case how CheckPoint will choose them? and how will it know about primary channel outage? etc&lt;/P&gt;&lt;P&gt;Please advise&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 22:07:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166852#M30052</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2023-01-05T22:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy with third party devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166855#M30053</link>
      <description>&lt;P&gt;Probably the best way to do it with third party devices is with VTIs and Dead Peer Detection.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jan 2023 23:24:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166855#M30053</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-05T23:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy with third party devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166858#M30054</link>
      <description>&lt;P&gt;thanks. How it should like from checkpoint side? Another community special for one site with two devices? how to change routing?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 00:21:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166858#M30054</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2023-01-06T00:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy with third party devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166864#M30055</link>
      <description>&lt;P&gt;Unfortunately this is a challenge and limitation I faced since beginning and AFAIK this is definitely not possible with checkpoint. Hence I started using different topology or devices like vyos or other routers for VPN IPsec.&lt;/P&gt;&lt;P&gt;Even you configure VTI - VTI is based on Ipsec and you need to have IPsec setup first since CheckPoint listens on only one interface this creates an issue. May be you could try MEP feature&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 02:08:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166864#M30055</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2023-01-06T02:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy with third party devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166871#M30061</link>
      <description>&lt;P&gt;Reality is,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;&amp;nbsp;is 100% correct. Truth is, making this work with CP is not so easy. MEP sounds like your best bet, because without it, CP will never know how to choose the right 3rd party device in case of failure.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 04:24:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166871#M30061</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-06T04:24:28Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy with third party devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166874#M30064</link>
      <description>&lt;P&gt;Thanks guys!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 04:27:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166874#M30064</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2023-01-06T04:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy with third party devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166876#M30066</link>
      <description>&lt;P&gt;For the reference:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/MEP.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/MEP.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 04:29:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166876#M30066</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-06T04:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN redundancy with third party devices</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166936#M30098</link>
      <description>&lt;P&gt;It’s a lot more complicated than that since you might need to redo the entire configuration as VTIs instead of using domain based VPN as mixing the two creates its own issue.&lt;BR /&gt;MEP might also work as well as others have suggested (but make sure that DPD is configured since that’s required for third party VPN endpoints).&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 14:20:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-redundancy-with-third-party-devices/m-p/166936#M30098</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-06T14:20:59Z</dc:date>
    </item>
  </channel>
</rss>

