<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN between on-premise cluster and Azure using VTI in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234790#M45514</link>
    <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk176249" target="_blank" rel="noopener"&gt;The Azure VWAN guide&lt;/A&gt; is very good, we used it for route-based VPN to Azure VPN gateways and it worked straight away.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Dec 2024 16:07:59 GMT</pubDate>
    <dc:creator>Alex-</dc:creator>
    <dc:date>2024-12-05T16:07:59Z</dc:date>
    <item>
      <title>VPN between on-premise cluster and Azure using VTI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234788#M45512</link>
      <description>&lt;P&gt;Evening all. I'm hopeful that someone can help me with this.&lt;/P&gt;&lt;P&gt;In the past I have successfully managed to set up a route-based VPN between a physical Check Point cluster and an AWS VPC by following the steps in &lt;A href="https://support.checkpoint.com/results/sk/sk100726" target="_self"&gt;sk100726&lt;/A&gt;, no problems there at all. Now I'm looking to configure something similar to an Azure Virtual Gateway using VTIs, but I'm struggling to find any reference documentation or process like the AWS one.&lt;/P&gt;&lt;P&gt;I've been playing around with it all day and I can't see a way to make it work, and I'm starting to wonder if it even is possible at all. I've looked at &lt;A href="https://support.checkpoint.com/results/sk/sk101275" target="_self"&gt;sk101275&lt;/A&gt; but I don't think it really applies to what I'm trying to achieve.&lt;/P&gt;&lt;P&gt;Has anyone successfully done this, and if so, how? What other options are there for creating an IPSEC VPN to Azure with a primary/backup configuration? BGP is not really an option in this scenario.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 15:52:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234788#M45512</guid>
      <dc:creator>khodgson_bts</dc:creator>
      <dc:date>2024-12-05T15:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between on-premise cluster and Azure using VTI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234790#M45514</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk176249" target="_blank" rel="noopener"&gt;The Azure VWAN guide&lt;/A&gt; is very good, we used it for route-based VPN to Azure VPN gateways and it worked straight away.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 16:07:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234790#M45514</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-12-05T16:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between on-premise cluster and Azure using VTI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234791#M45515</link>
      <description>&lt;P&gt;That seems to require BGP to work though. Have you done it without BGP? What IP's do you assign to the VTI's?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 16:10:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234791#M45515</guid>
      <dc:creator>khodgson_bts</dc:creator>
      <dc:date>2024-12-05T16:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between on-premise cluster and Azure using VTI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234793#M45517</link>
      <description>&lt;P&gt;See if below posts I made and responded to help. If not, message me, I have done this few times.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-failover-issue/m-p/155553#M26519" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-failover-issue/m-p/155553#M26519&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 16:36:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234793#M45517</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-05T16:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between on-premise cluster and Azure using VTI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234794#M45518</link>
      <description>&lt;P&gt;That looks very promising, thank you. I'll give it go.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 16:44:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234794#M45518</guid>
      <dc:creator>khodgson_bts</dc:creator>
      <dc:date>2024-12-05T16:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between on-premise cluster and Azure using VTI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234795#M45519</link>
      <description>&lt;P&gt;Sounds good!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 16:45:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234795#M45519</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-05T16:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between on-premise cluster and Azure using VTI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234799#M45520</link>
      <description>&lt;P&gt;By the way, since you mentioned BGP, I always found the ONLY way to make BGP work through the route based tunnel is to use UNNUMBERED VTIs, meaning it will "piggyback off" the main interface and when you configure it, it will have exact same IP in topology, but nothing to be alarmed about, its 100% normal.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 17:42:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234799#M45520</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-05T17:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between on-premise cluster and Azure using VTI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234800#M45521</link>
      <description>&lt;P&gt;I attached doc file with 3 screenshots I took, hope that also helps. Anyway, message me directly if you are not clear and we can do remote.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 18:17:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234800#M45521</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-05T18:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between on-premise cluster and Azure using VTI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234858#M45538</link>
      <description>&lt;P&gt;That's good to know. In this case I'm specifically looking to not use BGP. I'll let you know how I get on.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 09:13:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234858#M45538</guid>
      <dc:creator>khodgson_bts</dc:creator>
      <dc:date>2024-12-06T09:13:33Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between on-premise cluster and Azure using VTI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234866#M45542</link>
      <description>&lt;P&gt;This was very useful; I've managed to get it working. It's really not that different from the AWS process.&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 11:09:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234866#M45542</guid>
      <dc:creator>khodgson_bts</dc:creator>
      <dc:date>2024-12-06T11:09:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN between on-premise cluster and Azure using VTI</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234884#M45544</link>
      <description>&lt;P&gt;Of course, glad we can help. Yes, for regular route based, you can use either numbered or unnumbered, but I find using unnumbered is better, as you simply use vti to route the traffic when you create new routes and no need to be setting up new IPs. But again, works either way &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Glad you got it going.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2024 12:33:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/VPN-between-on-premise-cluster-and-Azure-using-VTI/m-p/234884#M45544</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-12-06T12:33:34Z</dc:date>
    </item>
  </channel>
</rss>

