<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN link selection question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173412#M31523</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;! Never seen that sk before, but good to know, though I believe you are right, probably not supported in new versions. For your 2nd point, customer has only 1 external interface, so not sure that might be feasible. What about below setting, would this work possibly?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19895i2AED71B226CFCFB2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;Thoughts?&lt;/P&gt;</description>
    <pubDate>Thu, 02 Mar 2023 20:17:41 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-03-02T20:17:41Z</dc:date>
    <item>
      <title>VPN link selection question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173395#M31520</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;I honestly was not even going to post this, but had to, just for my own sanity : - ). Though Im 99.99% sure this is NOT possible, but since customer asked me, figured would pick ya'll brains. So, here is their question...is there ANY way to configure CP firewall (either via link selection or any other way) to use say external IP for specific VPN tunnels and then use a different IP for other tunnels?&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 19:12:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173395#M31520</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-02T19:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: VPN link selection question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173407#M31522</link>
      <description>&lt;P&gt;In the past this was possible via entry in user.def see&amp;nbsp;&lt;A title="Controlling which IP address VPN traffic passes through" href="https://support.checkpoint.com/results/sk/sk31102" target="_blank" rel="noopener"&gt;Controlling which IP address VPN traffic passes through&lt;/A&gt;&amp;nbsp;But I think ther‘s no support for this in the newer releases.&lt;/P&gt;
&lt;P&gt;With link selection you can achieve this if the remote VPN gateways are available via different interface. You can route tunnel A via interface A and tunnel B via interface B, it depends on routing configuration. Source IP will be the interface IP of the outgoing interface.&amp;nbsp;&lt;A title="How to create VPN tunnels to a 3rd party peer using a specific ISP" href="https://support.checkpoint.com/results/sk/sk180613" target="_blank" rel="noopener"&gt;How to create VPN tunnels to a 3rd party peer using a specific ISP&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 20:14:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173407#M31522</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-03-02T20:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN link selection question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173412#M31523</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;! Never seen that sk before, but good to know, though I believe you are right, probably not supported in new versions. For your 2nd point, customer has only 1 external interface, so not sure that might be feasible. What about below setting, would this work possibly?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19895i2AED71B226CFCFB2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;Thoughts?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 20:17:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173412#M31523</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-02T20:17:41Z</dc:date>
    </item>
    <item>
      <title>Re: VPN link selection question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173421#M31532</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp; the shown settings are for &amp;nbsp;the IP addresses they will be probed from the remote gateway to the local gateway (see description in the top) Additional you have to configure the IP address of the outgoing packets, second part of your shown screen. But I think your need does not work if all tunnel packets are going through the same interface.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 20:30:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173421#M31532</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-03-02T20:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN link selection question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173427#M31533</link>
      <description>&lt;P&gt;Thanks mate, I think what you gave is the closest to what they need, so I greatly appreciate it &lt;span class="lia-unicode-emoji" title=":raising_hands:"&gt;🙌&lt;/span&gt;&lt;span class="lia-unicode-emoji" title=":raising_hands:"&gt;🙌&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 20:54:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173427#M31533</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-02T20:54:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN link selection question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173435#M31534</link>
      <description>&lt;P&gt;You can configure Remote Access and Site-to-Site VPN tunnels with a different "Link Selection" IP.&lt;BR /&gt;However, you cannot configure "per peer" Link Selection, which is what it sounds like your customer wants.&lt;BR /&gt;Though &lt;A href="https://support.checkpoint.com/results/sk/sk31102" target="_self"&gt;sk31102&lt;/A&gt; does seem like it would support that (if it works on current versions).&lt;/P&gt;
&lt;P&gt;FYI, in R82, I believe we are overhauling the whole "Link Selection" mechanism.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 21:29:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173435#M31534</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-02T21:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN link selection question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173440#M31535</link>
      <description>&lt;P&gt;Fair enough, thank you. Its weird how this client has route based tunnels configured (never seen that in 15 years with CP), so makes it a bit tricky to do all this, but you guys gave me excellent choice, so I will give this to them, probably tomorrow or some time next week. They understand the situation, so really this is the best they can get, whether they like it or not &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Thanks a lot as always&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 22:49:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173440#M31535</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-02T22:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN link selection question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173453#M31538</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;...I assume you were referring to visitor mode setting for remote access where it lets you select the interface?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 00:22:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173453#M31538</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-03T00:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN link selection question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173454#M31539</link>
      <description>&lt;P&gt;No, I'm referring to:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk32229" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk32229&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 00:28:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173454#M31539</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-03T00:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: VPN link selection question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173456#M31541</link>
      <description>&lt;P&gt;Ah, right...I remember seeing this sk couple of years ago.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Mar 2023 00:52:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-link-selection-question/m-p/173456#M31541</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-03-03T00:52:07Z</dc:date>
    </item>
  </channel>
</rss>

