<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Config VPN 2S2 with 2 Public IPs to 2 different sites in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Config-VPN-2S2-with-2-Public-IPs-to-2-different-sites/m-p/182194#M33389</link>
    <description>&lt;P&gt;Unfortunately, you cannot configure a different Link Selection IP for a different VPN peer directly; this is currently an RFE.&lt;BR /&gt;The only way to use a different IP for a different VPN peer is to route the traffic out a different physical interface and configure Link Selection accordingly.&lt;/P&gt;</description>
    <pubDate>Thu, 25 May 2023 20:22:45 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-05-25T20:22:45Z</dc:date>
    <item>
      <title>Config VPN 2S2 with 2 Public IPs to 2 different sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Config-VPN-2S2-with-2-Public-IPs-to-2-different-sites/m-p/181841#M33282</link>
      <description>&lt;P&gt;Hi guy!,&lt;/P&gt;&lt;P&gt;Currently, i am having a problem with configuring 2S2 VPN on checkpoint. Specifically we have 2 VPN lines to 2 different sites&lt;/P&gt;&lt;P&gt;Now the ftth lines are plugged into Peplink and we have a connection between Peplink and Checkpoint.&lt;/P&gt;&lt;P&gt;Currently we have preconfigured an s2s to 1 Site. In the link selection we choose&amp;nbsp;&lt;SPAN&gt;select&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Statically NATed IP&amp;nbsp;and this tunnel is running very stable.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;To be able to further configure the 2nd Tunnel, how should we choose link selection?&lt;/P&gt;&lt;P&gt;Has anyone come across this situation?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;LI-PRODUCT title="Harmony Remote Access VPN" id="remote-access-vpn"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Security Gateways" id="Security-Gateways"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 03:04:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Config-VPN-2S2-with-2-Public-IPs-to-2-different-sites/m-p/181841#M33282</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2023-05-24T03:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: Config VPN 2S2 with 2 Public IPs to 2 different sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Config-VPN-2S2-with-2-Public-IPs-to-2-different-sites/m-p/182022#M33340</link>
      <description>&lt;P&gt;It's not clear what you're trying to do here.&lt;BR /&gt;Can you elaborate more about the current and desired state?&lt;BR /&gt;More specifically:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Version/JHF of the Check Point device&lt;/LI&gt;
&lt;LI&gt;What device is the Check Point terminating a VPN to?&lt;/LI&gt;
&lt;LI&gt;What kind of VPN is being set up here? Route based? Domain based? If domain based, what is the remote encryption domain?&lt;/LI&gt;
&lt;LI&gt;Is your goal to establish two VPN tunnels to the same device or are you trying to establish a VPN to a different device?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;The more details you can provide, the better.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2023 20:34:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Config-VPN-2S2-with-2-Public-IPs-to-2-different-sites/m-p/182022#M33340</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-24T20:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: Config VPN 2S2 with 2 Public IPs to 2 different sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Config-VPN-2S2-with-2-Public-IPs-to-2-different-sites/m-p/182058#M33350</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;, thanks for your response,&lt;/P&gt;&lt;P&gt;1. I have 2 devices Checkpoint Gateway version R81.10/HF take 94.&lt;/P&gt;&lt;P&gt;2. The remote peer is a 3rd party device but I don't know which provider it is.&lt;/P&gt;&lt;P&gt;3. The VPN set up here is the:&lt;/P&gt;&lt;P&gt;In the IP Selection by Remote Peer,&lt;/P&gt;&lt;P&gt;we choose "Statically Nated IP"&amp;nbsp;We enter the Public IP in this section, because our checkpoint device is behind the Peplink device, and Peplink plays the role of NAT data output.&lt;/P&gt;&lt;P&gt;In the Outgoing Route Selection,&lt;/P&gt;&lt;P&gt;we choose "Operating system routing table"&lt;/P&gt;&lt;P&gt;&amp;nbsp;4.&amp;nbsp;As I described, we have 2 tunnels that need to be set up to 2 different sites.&amp;nbsp;We have now configured a tunnel to a site according to the configuration shown in the attached figure.&lt;/P&gt;&lt;P&gt;The problem we are facing is how to configure one more tunnel. While in the "Statically Nated IP" section, only one Public IP is allowed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 02:14:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Config-VPN-2S2-with-2-Public-IPs-to-2-different-sites/m-p/182058#M33350</guid>
      <dc:creator>MarcuzShinz</dc:creator>
      <dc:date>2023-05-25T02:14:16Z</dc:date>
    </item>
    <item>
      <title>Re: Config VPN 2S2 with 2 Public IPs to 2 different sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Config-VPN-2S2-with-2-Public-IPs-to-2-different-sites/m-p/182194#M33389</link>
      <description>&lt;P&gt;Unfortunately, you cannot configure a different Link Selection IP for a different VPN peer directly; this is currently an RFE.&lt;BR /&gt;The only way to use a different IP for a different VPN peer is to route the traffic out a different physical interface and configure Link Selection accordingly.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2023 20:22:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Config-VPN-2S2-with-2-Public-IPs-to-2-different-sites/m-p/182194#M33389</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-25T20:22:45Z</dc:date>
    </item>
  </channel>
</rss>

