<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN S2S 2 ISPs + AWS in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194726#M36262</link>
    <description>&lt;P&gt;We had a client who wanted similar thing and we did end up using BGP, though this was Azure, but literally the same concept.&lt;/P&gt;</description>
    <pubDate>Tue, 10 Oct 2023 20:55:42 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-10-10T20:55:42Z</dc:date>
    <item>
      <title>VPN S2S 2 ISPs + AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194336#M36153</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have a cluster on R81.10, in which we have two links/ISP from different suppliers. We would like to enable redundancy for a VPN with AWS.&lt;BR /&gt;EX:&lt;BR /&gt;ISP 1&lt;BR /&gt;ISP2&lt;/P&gt;&lt;P&gt;In other words, having 2 active tunnels, when the ISP1 tunnel fails, the ISP2 tunnel is activated.&lt;/P&gt;&lt;P&gt;As we know that S2S VPNs with AWS are route based, we have already ruled out using link selection.&lt;/P&gt;&lt;P&gt;In a first conversation with AWS, they informed us that it will have to be done via BGP.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Has anyone already implemented this configuration?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Oct 2023 18:38:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194336#M36153</guid>
      <dc:creator>IMCristian_Rosa</dc:creator>
      <dc:date>2023-10-05T18:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S 2 ISPs + AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194483#M36188</link>
      <description>&lt;P&gt;Why not use MEP? It applies if you have more than 1 center gateway, unless you are strictly referring to ISP redundancy?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/MEP.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/MEP.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 08 Oct 2023 21:57:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194483#M36188</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-08T21:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S 2 ISPs + AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194487#M36189</link>
      <description>&lt;P&gt;Hello, The_Rock,&lt;BR /&gt;&lt;BR /&gt;Tks for feedback.&lt;BR /&gt;&lt;BR /&gt;What I need is ISP redundancy to have redundancy between two tunnels.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Tks&lt;BR /&gt;&lt;BR /&gt;Cristian Rosa&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 00:51:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194487#M36189</guid>
      <dc:creator>IMCristian_Rosa</dc:creator>
      <dc:date>2023-10-09T00:51:12Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S 2 ISPs + AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194488#M36190</link>
      <description>&lt;P&gt;Hey mate,&lt;/P&gt;
&lt;P&gt;Not so sure thats possible, because if you think about it logically, how would the AWS side ever know that there was ISP like change and would be aware of new external IP?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 01:44:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194488#M36190</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-09T01:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S 2 ISPs + AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194568#M36222</link>
      <description>&lt;P&gt;Have you tried this? &lt;A href="https://support.checkpoint.com/results/sk/sk108958" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108958&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 19:47:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194568#M36222</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-09T19:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S 2 ISPs + AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194707#M36256</link>
      <description>&lt;P&gt;Andy,&lt;/P&gt;&lt;P&gt;This scenario is common, how would I do VPN redundancy using VTI/AWS?&lt;/P&gt;&lt;P&gt;Is there no possibility?&lt;/P&gt;&lt;P&gt;Tks&lt;/P&gt;&lt;P&gt;Cristian Rosa&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 19:08:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194707#M36256</guid>
      <dc:creator>IMCristian_Rosa</dc:creator>
      <dc:date>2023-10-10T19:08:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S 2 ISPs + AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194708#M36257</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello, PhoneBoy&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Tks for feedback.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;What I need is ISP redundancy to have redundancy between two tunnels.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 19:08:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194708#M36257</guid>
      <dc:creator>IMCristian_Rosa</dc:creator>
      <dc:date>2023-10-10T19:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S 2 ISPs + AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194715#M36259</link>
      <description>&lt;P&gt;From sk108958: "To detect when a tunnel goes down and to route traffic through the second tunnel, we use BGP."&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 20:16:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194715#M36259</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-10T20:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S 2 ISPs + AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194719#M36261</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;But in this case, the reference is to the second tunnel on the AWS side. In AWS there will be redundancy, but on the Checkpoint side.&lt;/P&gt;&lt;P&gt;Note that there is only one peer/ISP on the Checkpoint side.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn aws.png" style="width: 430px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22737iAD4A2C07EE5BAA9B/image-dimensions/430x394?v=v2" width="430" height="394" role="button" title="vpn aws.png" alt="vpn aws.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Tks&lt;/P&gt;&lt;P&gt;Cristian Rosa&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 20:25:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194719#M36261</guid>
      <dc:creator>IMCristian_Rosa</dc:creator>
      <dc:date>2023-10-10T20:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN S2S 2 ISPs + AWS</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194726#M36262</link>
      <description>&lt;P&gt;We had a client who wanted similar thing and we did end up using BGP, though this was Azure, but literally the same concept.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Oct 2023 20:55:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-S2S-2-ISPs-AWS/m-p/194726#M36262</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-10-10T20:55:42Z</dc:date>
    </item>
  </channel>
</rss>

