<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VSX VTI with static routes in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VTI-with-static-routes/m-p/195134#M36306</link>
    <description>&lt;P&gt;I don't believe this is unsupported...otherwise, this thread would not have happened:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Routing-not-working-towards-VTI/m-p/121522#M17310" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Routing-not-working-towards-VTI/m-p/121522#M17310&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would check with the TAC: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Oct 2023 20:32:15 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-10-13T20:32:15Z</dc:date>
    <item>
      <title>VSX VTI with static routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VTI-with-static-routes/m-p/195106#M36305</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any plans to enable static routing for VTI's in VSX?&lt;/P&gt;&lt;P&gt;I've created the VTI as per the manual (R81.10 manager and gateway), and got the interface in topology. However it doesn't add a route for the peer IP into the table, which means that any static routes via peer IP are unresolvable and thus rejected.&lt;/P&gt;&lt;P&gt;Ideally we'd have unnumbered tunnels and routing with interface next-hops, but that's still not supported either &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Jamie&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 16:41:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VTI-with-static-routes/m-p/195106#M36305</guid>
      <dc:creator>stallwoodj</dc:creator>
      <dc:date>2023-10-13T16:41:03Z</dc:date>
    </item>
    <item>
      <title>Re: VSX VTI with static routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VTI-with-static-routes/m-p/195134#M36306</link>
      <description>&lt;P&gt;I don't believe this is unsupported...otherwise, this thread would not have happened:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Routing-not-working-towards-VTI/m-p/121522#M17310" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Routing-not-working-towards-VTI/m-p/121522#M17310&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would check with the TAC: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 20:32:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VTI-with-static-routes/m-p/195134#M36306</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-10-13T20:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: VSX VTI with static routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VTI-with-static-routes/m-p/195142#M36307</link>
      <description>&lt;P&gt;R81 introduced VTI support for VSX but only with dynamic routing to my knowledge.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"Configure Dynamic Routing VPN through Virtual Tunnel Interface (VTI) in VSX mode."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Maybe post R82 but please check it with your local SE who can raise any needed RFEs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2023 23:54:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VTI-with-static-routes/m-p/195142#M36307</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-10-13T23:54:27Z</dc:date>
    </item>
    <item>
      <title>Re: VSX VTI with static routes</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VTI-with-static-routes/m-p/195661#M36456</link>
      <description>&lt;P&gt;As it happens it turned out when I ran the vsx_util to create the VTI, it allowed me to use the same IP for BOTH ends of the numbered tunnel, without an error being thrown up either on the tool or in the vFW network topology!&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I deleted and re-added the tunnel with the correct IP's a /32 route for the remote IP was injected into the VSX routing, with static routes to the remote IP appearing to be accepted (though I didn't confirm they actually did work).&lt;/P&gt;</description>
      <pubDate>Thu, 19 Oct 2023 16:25:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VSX-VTI-with-static-routes/m-p/195661#M36456</guid>
      <dc:creator>stallwoodj</dc:creator>
      <dc:date>2023-10-19T16:25:09Z</dc:date>
    </item>
  </channel>
</rss>

