<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mulitple 5 site vpn design  P2P and mesh and center between them in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180805#M33050</link>
    <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;&amp;nbsp;said...route based tunnels.&lt;/P&gt;</description>
    <pubDate>Sat, 13 May 2023 15:46:58 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-05-13T15:46:58Z</dc:date>
    <item>
      <title>Mulitple site vpn design  P2P</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180784#M33045</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="E &amp;amp; B is directly connected vpn" style="width: 861px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20895i5F178C23E59EB4C4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture1.JPG" alt="E &amp;amp; B is directly connected vpn" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;E &amp;amp; B is directly connected vpn&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;++&amp;nbsp;&lt;SPAN&gt;E &amp;amp; B need to be directly through P2P vpn&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;++ D &amp;amp; C need to be directly through P2P vpn&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2023 03:41:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180784#M33045</guid>
      <dc:creator>gajendra229</dc:creator>
      <dc:date>2023-05-13T03:41:41Z</dc:date>
    </item>
    <item>
      <title>Mulitple 5 site vpn design  P2P and mesh and center between them</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180783#M33049</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture1.JPG" style="width: 861px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20894iDCC1DABBDA7A1B90/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture1.JPG" alt="Capture1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;++ E &amp;amp; B need to directly connect to each other through direct tunnel&lt;/P&gt;&lt;P&gt;++ D &amp;amp; A&amp;nbsp;need to directly connect to each other through direct tunnel&lt;/P&gt;&lt;P&gt;How this can be achieved ?&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2023 03:23:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180783#M33049</guid>
      <dc:creator>gajendra229</dc:creator>
      <dc:date>2023-05-13T03:23:42Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitple site vpn design  P2P</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180791#M33047</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/85012"&gt;@gajendra229&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This forum is not for suggestion on designing the networks and extend help in designing the same but we can help you on technical issues if any. However to give you a hint you can use route based tunnels.&lt;/P&gt;&lt;P&gt;Or best way opt for DMVPN with other devices; this would not be possible with policy based tunnels.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2023 07:28:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180791#M33047</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2023-05-13T07:28:03Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitple site vpn design  P2P</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180796#M33048</link>
      <description>&lt;P&gt;Thanks, Blason for replying,&lt;/P&gt;&lt;P&gt;Sorry if i said need help to design....&lt;/P&gt;&lt;P&gt;I already have this design just trying to understand how do i can achieve this configuration.&lt;BR /&gt;&lt;BR /&gt;Route based tunnels any url where i can learn and configure according to it on checkpoint R80.40?&lt;/P&gt;&lt;P&gt;as i configured vpn domain based tunnel only never configured route-based tunnel.&lt;/P&gt;&lt;P&gt;Does this route-based tunnel require, Routing team to do something differently? mean i need to inform something to configure accroding to configuration in checkpoint?&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2023 08:10:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180796#M33048</guid>
      <dc:creator>gajendra229</dc:creator>
      <dc:date>2023-05-13T08:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitple 5 site vpn design  P2P and mesh and center between them</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180805#M33050</link>
      <description>&lt;P&gt;As&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1551"&gt;@Blason_R&lt;/a&gt;&amp;nbsp;said...route based tunnels.&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2023 15:46:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180805#M33050</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-13T15:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitple 5 site vpn design  P2P and mesh and center between them</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180806#M33051</link>
      <description>&lt;P&gt;I got that but didn't understand the concept of creating between this many tunnels per my design , what should be the approach&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2023 17:33:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180806#M33051</guid>
      <dc:creator>gajendra229</dc:creator>
      <dc:date>2023-05-13T17:33:14Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitple 5 site vpn design  P2P and mesh and center between them</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180807#M33052</link>
      <description>&lt;P&gt;Below is good reference, but I also pasted some notes I took for myself. I would send you the good doc I have, but it contains private customer info, so cant do that, sorry&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk100726" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk100726&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Some notes I gathered:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;Steps for route based azure vpn tunnel:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;Star community&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;Get all the settings from config file on Azure side&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;Pick any Ips from 169.254.0.0/24 subnet NOT in use with current tunnels for VTIs/remote address&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;Say:&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;169.254.0.200, 201 and 202 (master, backup and VIP) and then .203 for remote address (which is also used as DG for subnet on the other side)&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;Once this is configured, get interfaces without TOPOLOGY&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;*DO NOT PUSH POLICY YET*&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;Save changes in dashboard, then add peer external IP to exempt anti spoof group for external interface&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;Then also add route to external peer IP using actual Internet default DG&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;MAKE SURE PEER NAME (in VTI settings in web UI) MATCHES WITH INTEROPERABLE OBJECT in dashboard&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;Create appropriate rule using VPN community (bi-directional match) (internal clear to 3rd party tunnel, 3rd party to 3 rd party, 3rd party to internal clear in vpn column)&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in; font-family: Calibri; font-size: 16.0pt;"&gt;Push policy and test&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2023 17:43:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180807#M33052</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-13T17:43:56Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitple 5 site vpn design  P2P and mesh and center between them</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180808#M33053</link>
      <description>&lt;P&gt;Thanks for sharing that any reference doc that can help to build multiple tunnels under same management server&lt;/P&gt;&lt;P&gt;I have 5 gateway, per my design I don't understand how many tunnel have to build&lt;/P&gt;&lt;P&gt;thinking to create 3 route based tunnels as if create domain based it will give an error while pushing policy on firewall&lt;/P&gt;&lt;P&gt;The pair of objects &amp;lt;FW A and FW b&amp;gt; appear simultaneously in the Intranet Communities:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;not sure if i can achieve thinks with below 3 tunnels&lt;/P&gt;&lt;P&gt;ABC - mesh&lt;BR /&gt;A center gateway, E,D,C satellite gateway - bidirectional flow&lt;BR /&gt;C center gateway D,B,E satellite gateway&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2023 18:07:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180808#M33053</guid>
      <dc:creator>gajendra229</dc:creator>
      <dc:date>2023-05-13T18:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: Mulitple 5 site vpn design  P2P and mesh and center between them</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180810#M33054</link>
      <description>&lt;P&gt;I would contact TAC for faster resolution.&lt;/P&gt;</description>
      <pubDate>Sat, 13 May 2023 18:53:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mulitple-site-vpn-design-P2P/m-p/180810#M33054</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-13T18:53:05Z</dc:date>
    </item>
  </channel>
</rss>

