<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: S2S VPN primary and backup (DR) location in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172715#M31401</link>
    <description>&lt;P&gt;No need to post the VPN Admin Guide, i have it ! Never saw MEP in use, though...&lt;/P&gt;</description>
    <pubDate>Sat, 25 Feb 2023 11:20:03 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2023-02-25T11:20:03Z</dc:date>
    <item>
      <title>S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172630#M31374</link>
      <description>&lt;P&gt;Hello, I need to accomplish this scenario (attached picture). I need to setup S2S VPN tunnels on CheckPoint ClusterXL towards Site 1 (primary location) and Site 2 (backup DR location). Idea is, when primary location falls down, everything works over backup DR location without interrupt.&lt;/P&gt;&lt;P&gt;How can I do that?&lt;/P&gt;&lt;P&gt;Additional questions:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Is it possible to have Policy Based VPN toward Site 1 and Route Based VPN toward Site 2?&lt;/LI&gt;&lt;LI&gt;If 1. is not possible which one is better to use Policy Based or Route Based VPN on Site 1 and Site 2&lt;/LI&gt;&lt;LI&gt;Can I use MEP (Multiple Entry Point) in this scenario?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Milan Babic&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 10:43:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172630#M31374</guid>
      <dc:creator>babicmilan</dc:creator>
      <dc:date>2023-02-24T10:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172631#M31375</link>
      <description>&lt;P&gt;1. Is it possible to have Policy Based VPN toward Site 1 and Route Based VPN toward Site 2?&lt;/P&gt;
&lt;P&gt;Why that demand, and why will community based VPN not work for you ? As seen in &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100500&amp;amp;partition=Basic&amp;amp;product=Quantum" target="_blank"&gt;sk100500: Policy-Based &lt;STRONG&gt;Routing&lt;/STRONG&gt; (PBR) on Gaia OS&lt;/A&gt;&amp;nbsp;and &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167135&amp;amp;partition=Advanced&amp;amp;product=Quantum" target="_blank"&gt;sk167135: Policy-Based &lt;STRONG&gt;Routing&lt;/STRONG&gt; and Application-Based &lt;STRONG&gt;Routing&lt;/STRONG&gt; in Gaia&lt;/A&gt;,&amp;nbsp;this is used for other reasons, not VPN. What is possible is to use both community and route based VPN: &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109340&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;sk109340: Mixing &lt;STRONG&gt;Route&lt;/STRONG&gt; &lt;STRONG&gt;Based&lt;/STRONG&gt; &lt;STRONG&gt;VPN&lt;/STRONG&gt; with Domain &lt;STRONG&gt;Based&lt;/STRONG&gt; &lt;STRONG&gt;VPN&lt;/STRONG&gt; on the same Security Gateway&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2. If 1. is not possible which one is better to use Policy Based or Route Based VPN on Site 1 and Site 2&lt;/P&gt;
&lt;P&gt;Community based routing is the standard deployment for most circumstances; also see 1.&lt;/P&gt;
&lt;P&gt;3. Can I use MEP (Multiple Entry Point)&lt;/P&gt;
&lt;P&gt;MEP is for RA VPN only, so it is unclear what this question for S2S VPN means ?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 11:02:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172631#M31375</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-24T11:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172637#M31376</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;Let's clarify, when I say "Policy Based VPN" I think on "Domain Based VPN".&lt;/P&gt;&lt;P&gt;I have attached Site to Site VPN &lt;SPAN class=""&gt;R81.10 Administration Guide&lt;/SPAN&gt; where MEP is explained.&lt;/P&gt;&lt;P&gt;1) S2S VPN tunnel between HQ and Site 1 is operational (Domain Based VPN), tunnel between HQ and Site 2 I need to configure.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 11:16:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172637#M31376</guid>
      <dc:creator>babicmilan</dc:creator>
      <dc:date>2023-02-24T11:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172668#M31384</link>
      <description>&lt;P&gt;Check:&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk164355" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk164355&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 16:12:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172668#M31384</guid>
      <dc:creator>Machine_Head</dc:creator>
      <dc:date>2023-02-24T16:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172684#M31389</link>
      <description>&lt;P&gt;I second what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/87513"&gt;@Machine_Head&lt;/a&gt;&amp;nbsp;gave you. Had customer do this couple of years back and it worked flawlessly.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 19:40:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172684#M31389</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-24T19:40:12Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172685#M31390</link>
      <description>&lt;P&gt;Also, to add, IF you have ISP redundancy, just know that any new VPN connections would NOT survive isp failure link. Something to keep in mind, if you do have that configured.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Feb 2023 19:45:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172685#M31390</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-24T19:45:11Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172714#M31400</link>
      <description>&lt;P&gt;As i wrote: What is possible is to use both community and route based VPN: &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109340&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank" rel="noopener noreferrer"&gt;sk109340: Mixing &lt;STRONG&gt;Route&lt;/STRONG&gt; &lt;STRONG&gt;Based&lt;/STRONG&gt; &lt;STRONG&gt;VPN&lt;/STRONG&gt; with Domain &lt;STRONG&gt;Based&lt;/STRONG&gt; &lt;STRONG&gt;VPN&lt;/STRONG&gt; on the same Security Gateway&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Feb 2023 11:18:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172714#M31400</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-25T11:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172715#M31401</link>
      <description>&lt;P&gt;No need to post the VPN Admin Guide, i have it ! Never saw MEP in use, though...&lt;/P&gt;</description>
      <pubDate>Sat, 25 Feb 2023 11:20:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172715#M31401</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-02-25T11:20:03Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172811#M31420</link>
      <description>&lt;P&gt;OK, that means it is not possible to mix Route Based VPN and Domain Based VPN toward same destination because Domain Based VPN will always take precedence? Is there a way to change this behavior by some policy order?&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 11:33:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172811#M31420</guid>
      <dc:creator>babicmilan</dc:creator>
      <dc:date>2023-02-27T11:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172818#M31421</link>
      <description>&lt;P&gt;As far as Im aware, no and no. Sorry, I meant YES, domain based will take presedence and NO, you cant change the bahavior by policy order.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 12:30:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/172818#M31421</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-02-27T12:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/173173#M31467</link>
      <description>&lt;P&gt;&lt;U&gt;Another questions:&lt;/U&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;In my topology if I use MEP star community HQ (CheckPoint ClusterXL) would be Satellite Gateway, Site1 and Site2 would be Center Gateways? How to configure "VPN Routing" in this star community? VPN tunnel must be initiated from HQ towards Site1 and Site2&lt;/LI&gt;&lt;LI&gt;Can I use Route Based VPN with MEP or it must be Community Based VPN?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Wed, 01 Mar 2023 12:26:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/173173#M31467</guid>
      <dc:creator>babicmilan</dc:creator>
      <dc:date>2023-03-01T12:26:47Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/173176#M31468</link>
      <description>&lt;P&gt;-Yes&lt;/P&gt;&lt;P&gt;-To center only should be fine.&lt;/P&gt;&lt;P&gt;- It doesn't matter from where the traffic is initiated.&lt;/P&gt;&lt;P&gt;-As i&amp;nbsp; understand it, MEP is to be used with Domain Based VPN. Potentially if you use routing there is no need for MEP as the routing decision comes from the routing protocol.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Juan&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 12:33:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/173176#M31468</guid>
      <dc:creator>Machine_Head</dc:creator>
      <dc:date>2023-03-01T12:33:16Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/173184#M31474</link>
      <description>&lt;P&gt;It is possible as source AND destination must match Domains, see &lt;A class="cp_link sc_ellipsis" style="max-width: 840px;" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk109340&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank" rel="noopener noreferrer"&gt;sk109340&lt;/A&gt; !&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 12:49:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/173184#M31474</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-01T12:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/173187#M31475</link>
      <description>&lt;P&gt;Second what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/87513"&gt;@Machine_Head&lt;/a&gt;&amp;nbsp;told you.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 12:57:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/173187#M31475</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-01T12:57:00Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/173188#M31476</link>
      <description>&lt;P&gt;MEP is enabled in VPN Community, but not &lt;SPAN&gt;implicit MEP - see &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/MEP.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/MEP.htm&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 12:58:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/173188#M31476</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-03-01T12:58:18Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/175140#M31919</link>
      <description>&lt;P&gt;Hello, I have created VPN star topology, "CP-ZZZRS" as satellite gateway, "VPN_PURS_GW" and "VPN_PURS_DR_GW" as center gateways. I have MEP enabled. I want to achieve that S2S tunnel between gateways "CP-ZZZRS" and "VPN_PURS_GW" has higher priority.&lt;/P&gt;&lt;P&gt;I'm not sure that I have configure it correctly, I want to be sure. (atached picture).&lt;/P&gt;&lt;P&gt;Please look at default priority rules, exception priority rules, for "Advanced" I have choose "First to respond".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Milan Babic&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 17:56:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/175140#M31919</guid>
      <dc:creator>babicmilan</dc:creator>
      <dc:date>2023-03-16T17:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: S2S VPN primary and backup (DR) location</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/175147#M31920</link>
      <description>&lt;P&gt;I remember few years ago customer had it set exactly the same way and worked fine. Seems totally logical to me.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 18:09:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/S2S-VPN-primary-and-backup-DR-location/m-p/175147#M31920</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-16T18:09:18Z</dc:date>
    </item>
  </channel>
</rss>

