<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Checkpoint cluster Site-ti-Site VPN - PaloAlto (Dual ISP) Fails Over in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-cluster-Site-ti-Site-VPN-PaloAlto-Dual-ISP-Fails-Over/m-p/230110#M44284</link>
    <description>&lt;P&gt;Dear mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a scenario, a PaloAlot having two ISP and we want to configure two VPN links to Checkpoint cluster single ISP.&lt;/P&gt;&lt;P&gt;From Palo Alto, there is a tunnel IF with a private IP that you can use for failover monitoring, but on the Checkpoint end, the packet comes and decrypted with action drop since the IP is also part of the internal range.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On checkpoint, I set up a single VPN community (STAR), with checkpoint as the center and two PaloAlto objects satellite (same domain subnet).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any guide regarding this case?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
    <pubDate>Fri, 18 Oct 2024 08:06:11 GMT</pubDate>
    <dc:creator>SdanteMate</dc:creator>
    <dc:date>2024-10-18T08:06:11Z</dc:date>
    <item>
      <title>Checkpoint cluster Site-ti-Site VPN - PaloAlto (Dual ISP) Fails Over</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-cluster-Site-ti-Site-VPN-PaloAlto-Dual-ISP-Fails-Over/m-p/230110#M44284</link>
      <description>&lt;P&gt;Dear mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a scenario, a PaloAlot having two ISP and we want to configure two VPN links to Checkpoint cluster single ISP.&lt;/P&gt;&lt;P&gt;From Palo Alto, there is a tunnel IF with a private IP that you can use for failover monitoring, but on the Checkpoint end, the packet comes and decrypted with action drop since the IP is also part of the internal range.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On checkpoint, I set up a single VPN community (STAR), with checkpoint as the center and two PaloAlto objects satellite (same domain subnet).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any guide regarding this case?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 08:06:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-cluster-Site-ti-Site-VPN-PaloAlto-Dual-ISP-Fails-Over/m-p/230110#M44284</guid>
      <dc:creator>SdanteMate</dc:creator>
      <dc:date>2024-10-18T08:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Checkpoint cluster Site-ti-Site VPN - PaloAlto (Dual ISP) Fails Over</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-cluster-Site-ti-Site-VPN-PaloAlto-Dual-ISP-Fails-Over/m-p/230179#M44298</link>
      <description>&lt;P&gt;This requires &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/MEP.htm" target="_self"&gt;MEP&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2024 18:55:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Checkpoint-cluster-Site-ti-Site-VPN-PaloAlto-Dual-ISP-Fails-Over/m-p/230179#M44298</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-18T18:55:42Z</dc:date>
    </item>
  </channel>
</rss>

