<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISP Load sharing exception for VPN peer in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Load-sharing-exception-for-VPN-peer/m-p/177054#M32441</link>
    <description>&lt;P&gt;No problem to use all three interfaces. If your local interface is only reachable via local routing not via the other ISPs it‘s no problem. But you have to configure properly the outgoing routing options and link probing.&lt;/P&gt;</description>
    <pubDate>Sun, 02 Apr 2023 19:26:03 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2023-04-02T19:26:03Z</dc:date>
    <item>
      <title>ISP Load sharing exception for VPN peer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Load-sharing-exception-for-VPN-peer/m-p/177012#M32431</link>
      <description>&lt;P&gt;we use star community pattern. there are 2 providers on central gateway and we want to enable ISP load sharing therefore we check "apply settings to vpn traffic" but there is a problem that one tunnel is built on gateway that's available on l2 channel (via local address on 3rd interface) without internet access. if we enable option i mentioned above then settings will affect link section and this vpn thus vpn tunnel(with local ip) will be built on gateways with internet access which leads to failure(vpn tunnel won't be built) is there any way to configure isp ls but make an exception for it?&lt;/P&gt;</description>
      <pubDate>Sun, 02 Apr 2023 11:14:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Load-sharing-exception-for-VPN-peer/m-p/177012#M32431</guid>
      <dc:creator>Andrey_Gl</dc:creator>
      <dc:date>2023-04-02T11:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Load sharing exception for VPN peer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Load-sharing-exception-for-VPN-peer/m-p/177021#M32434</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/53455"&gt;@Andrey_Gl&lt;/a&gt;&amp;nbsp;you can configure ISP redundancy without&amp;nbsp;&lt;SPAN&gt;"apply settings to vpn traffic".&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;With this setting the configuration for VPN link selection doesn‘t follow ISP redundancy configuration. You can configure VPN link selection with link probing to check which link is available.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Apr 2023 06:34:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Load-sharing-exception-for-VPN-peer/m-p/177021#M32434</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-04-03T06:34:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Load sharing exception for VPN peer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Load-sharing-exception-for-VPN-peer/m-p/177033#M32440</link>
      <description>&lt;P&gt;Thank you.&lt;SPAN&gt;Yes, I see that option, but if I enable it, won't I need to select three addresses there - two provider addresses and one local address of another peer? Won't they interfere with each other? In our installation, there are 10 VPN peers available through two interfaces looking to the Internet, and one VPN peer is available through a local interface.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 02 Apr 2023 18:54:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Load-sharing-exception-for-VPN-peer/m-p/177033#M32440</guid>
      <dc:creator>Andrey_Gl</dc:creator>
      <dc:date>2023-04-02T18:54:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Load sharing exception for VPN peer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Load-sharing-exception-for-VPN-peer/m-p/177054#M32441</link>
      <description>&lt;P&gt;No problem to use all three interfaces. If your local interface is only reachable via local routing not via the other ISPs it‘s no problem. But you have to configure properly the outgoing routing options and link probing.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Apr 2023 19:26:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Load-sharing-exception-for-VPN-peer/m-p/177054#M32441</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2023-04-02T19:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISP Load sharing exception for VPN peer</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Load-sharing-exception-for-VPN-peer/m-p/177065#M32443</link>
      <description>&lt;P&gt;Im fairly confident what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;&amp;nbsp;suggested will work, as I had customer do this in the past and that was perfect option to make it work as intended.&lt;/P&gt;</description>
      <pubDate>Sun, 02 Apr 2023 22:23:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ISP-Load-sharing-exception-for-VPN-peer/m-p/177065#M32443</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-02T22:23:21Z</dc:date>
    </item>
  </channel>
</rss>

