<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Interoperable IP Duplicate configuration in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-IP-Duplicate-configuration/m-p/167078#M30161</link>
    <description>&lt;P&gt;We have a requirement as below :&lt;/P&gt;&lt;P&gt;Currently, we have established IPSEC between Our Primary DC and One of the client's site firewalls and we are managing our Primary and DR DC checkpoint FW using the same Management server.&lt;/P&gt;&lt;P&gt;We must set up our DR center with the Same peer Gateway IP.&amp;nbsp; what is the recommended method to configure interoperable configuration, is it okay to duplicate the interoperable device witch we use in Production GW Cluster and the same Duplicate Current VPN domain?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Instead of using existing interoperable devices create another one in Documentation &amp;amp; administration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise are there any disadvantages create 2 interoperable device with same IP?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Jan 2023 11:13:25 GMT</pubDate>
    <dc:creator>Duminda_lakmal</dc:creator>
    <dc:date>2023-01-09T11:13:25Z</dc:date>
    <item>
      <title>VPN Interoperable IP Duplicate configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-IP-Duplicate-configuration/m-p/167078#M30161</link>
      <description>&lt;P&gt;We have a requirement as below :&lt;/P&gt;&lt;P&gt;Currently, we have established IPSEC between Our Primary DC and One of the client's site firewalls and we are managing our Primary and DR DC checkpoint FW using the same Management server.&lt;/P&gt;&lt;P&gt;We must set up our DR center with the Same peer Gateway IP.&amp;nbsp; what is the recommended method to configure interoperable configuration, is it okay to duplicate the interoperable device witch we use in Production GW Cluster and the same Duplicate Current VPN domain?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Instead of using existing interoperable devices create another one in Documentation &amp;amp; administration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise are there any disadvantages create 2 interoperable device with same IP?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 11:13:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-IP-Duplicate-configuration/m-p/167078#M30161</guid>
      <dc:creator>Duminda_lakmal</dc:creator>
      <dc:date>2023-01-09T11:13:25Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable IP Duplicate configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-IP-Duplicate-configuration/m-p/167106#M30182</link>
      <description>&lt;P&gt;External IP should not be a issue however the SIC IP has to be different. By the way how the peer will differentiate and establish VPN with same peer&amp;nbsp; IP? How will peer know which firewall to route the packet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the intention of this activity? I guess there are other ways to achieve the redundancy if you are planning for it then.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 12:44:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-IP-Duplicate-configuration/m-p/167106#M30182</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2023-01-09T12:44:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable IP Duplicate configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-IP-Duplicate-configuration/m-p/167156#M30198</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;Yes, our&amp;nbsp;&lt;SPAN&gt;intention&amp;nbsp;is High availability. Peer gateway ( I Mean Customer side Firewall).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;On our Side, we have a separate policy package for Primary &amp;amp; DR. currently we have one community with a production side cluster and Customer's side Firewall IP (Interoperable Device)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;we are going to create new VPN Community with mentioning DR Site CP Cluster and Client's side same Peer GW IP (Second interoperable Device - Duplicate as Primary side configures because peer GW and Domain same)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, we are asking customer to create new community including our DR site and their Gateways.&amp;nbsp;&lt;/P&gt;&lt;P&gt;(No Need automatic failover)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;***This is my Question We can use&lt;/P&gt;&lt;P&gt;1. only One interoperable device for both My side communities DR and Primary&lt;/P&gt;&lt;P&gt;2. Create Duplicate Interoperable same as Production site configures then apply new duplicated one for DR community configuration.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any limitation or misconfiguration when i duplicate Interoperable device in checkpoint environment?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I totally understand without duplicate we can do this, but this is for my understanding.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly help me clarify this point.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 17:11:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-IP-Duplicate-configuration/m-p/167156#M30198</guid>
      <dc:creator>Duminda_lakmal</dc:creator>
      <dc:date>2023-01-09T17:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable IP Duplicate configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-IP-Duplicate-configuration/m-p/167158#M30200</link>
      <description>&lt;P&gt;Nah - I dont think you will be able to do it on CheckPoint and yes Check Point wont be able to send a traffic if encryption_domains overlaps. You must think of something else; I have compiled vyos open source and then using it for all my site-site VPN configurations.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 17:18:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-IP-Duplicate-configuration/m-p/167158#M30200</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2023-01-09T17:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Interoperable IP Duplicate configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-IP-Duplicate-configuration/m-p/167159#M30201</link>
      <description>&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;&amp;nbsp;. Its highly unlikely you can do this with CP side.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 18:11:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-Interoperable-IP-Duplicate-configuration/m-p/167159#M30201</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-09T18:11:18Z</dc:date>
    </item>
  </channel>
</rss>

