<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Setup multiple VPN tunnel between checkpoint firewall and third-party endpoint in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setup-multiple-VPN-tunnel-between-checkpoint-firewall-and-third/m-p/167177#M30212</link>
    <description>&lt;P&gt;Hello experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to establish site to site vpn tunnel to third party through checkpoint firewall. Due to one tunnel bandwidth limitation, we need to setup multiple tunnels between them. We noticed there's problem to establish multiple between 2 endpoints. Just wondering if below solution will help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;client --&amp;gt; internal firewall --&amp;gt; external firewall --&amp;gt; third party endpoint&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will try to configure multiple VTI to different remote ip at internal firewall, So vpn tunnel will be between internal firewall and third party endpoint.&amp;nbsp; And we will nat VTI IP to different public ip address at external firewall and nat all remote ips to same third party endpoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So in theory, internal firewall will think it is connecting to multiple different endpoints. From third party point of view, all tunnel coming from different source.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then we add multiple static route at internal firewall pointing to same destination with same cost to achieve ECMP.&lt;/P&gt;&lt;P&gt;Is this solution possible?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
    <pubDate>Mon, 09 Jan 2023 20:26:24 GMT</pubDate>
    <dc:creator>FrankXie</dc:creator>
    <dc:date>2023-01-09T20:26:24Z</dc:date>
    <item>
      <title>Setup multiple VPN tunnel between checkpoint firewall and third-party endpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setup-multiple-VPN-tunnel-between-checkpoint-firewall-and-third/m-p/167177#M30212</link>
      <description>&lt;P&gt;Hello experts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are trying to establish site to site vpn tunnel to third party through checkpoint firewall. Due to one tunnel bandwidth limitation, we need to setup multiple tunnels between them. We noticed there's problem to establish multiple between 2 endpoints. Just wondering if below solution will help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;client --&amp;gt; internal firewall --&amp;gt; external firewall --&amp;gt; third party endpoint&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We will try to configure multiple VTI to different remote ip at internal firewall, So vpn tunnel will be between internal firewall and third party endpoint.&amp;nbsp; And we will nat VTI IP to different public ip address at external firewall and nat all remote ips to same third party endpoint.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So in theory, internal firewall will think it is connecting to multiple different endpoints. From third party point of view, all tunnel coming from different source.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then we add multiple static route at internal firewall pointing to same destination with same cost to achieve ECMP.&lt;/P&gt;&lt;P&gt;Is this solution possible?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for your response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 20:26:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setup-multiple-VPN-tunnel-between-checkpoint-firewall-and-third/m-p/167177#M30212</guid>
      <dc:creator>FrankXie</dc:creator>
      <dc:date>2023-01-09T20:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Setup multiple VPN tunnel between checkpoint firewall and third-party endpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setup-multiple-VPN-tunnel-between-checkpoint-firewall-and-third/m-p/167179#M30213</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/79384"&gt;@FrankXie&lt;/a&gt;&amp;nbsp;@very interesting idea but answer will be NO&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Between Check Points gateways you can use more then one link for a VPN connection and you can dorthin LoadSharing. But with third party, I‘m not aware of any solution.&lt;BR /&gt;&lt;SPAN&gt;How about your VPN bandwidth limitation? Let‘s talk about these limitation youˋre referring to, please explain.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 20:42:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setup-multiple-VPN-tunnel-between-checkpoint-firewall-and-third/m-p/167179#M30213</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-01-09T20:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Setup multiple VPN tunnel between checkpoint firewall and third-party endpoint</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setup-multiple-VPN-tunnel-between-checkpoint-firewall-and-third/m-p/167180#M30214</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please share more detail why it is not possible?&lt;/P&gt;&lt;P&gt;It is third party's limitation regarding bandwidth per tunnel. Take Zscaler as an example. Only 400M throughput supported per tunnel.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 20:51:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Setup-multiple-VPN-tunnel-between-checkpoint-firewall-and-third/m-p/167180#M30214</guid>
      <dc:creator>FrankXie</dc:creator>
      <dc:date>2023-01-09T20:51:55Z</dc:date>
    </item>
  </channel>
</rss>

