<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: P2P VPN Star Community - Link Selection Mode in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251422#M49218</link>
    <description>&lt;P&gt;Andy,&lt;/P&gt;&lt;P&gt;Thanks for the reply.&amp;nbsp; &amp;nbsp;First we are R82 and I have read the R82 VPN Admin Guide.&amp;nbsp; There is only 1 external, internet facing connection on these CP3200s.&amp;nbsp; So I am trying to understand if there is any benefit to change from Legacy to Enhanced.&amp;nbsp; I am always wary about changing a setting like this and not "seeing" what other settings need to change.&lt;/P&gt;&lt;P&gt;As for MEP, pretty sure I will need Implicit MEP that I specify the Priority - our corporate 5800 HA would be "Primary" and the D/R site's Fortigate (interoperable device) would be "Backup".&amp;nbsp; The docs become confusing when discussing defining the VPN domain.&amp;nbsp; In D/R situation, our servers and Internet would be up at the D/R site.&amp;nbsp; On pg 203, Config Implicit MEP,&amp;nbsp; it implies the backup Gateway is a CP device...&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Jun 2025 11:09:28 GMT</pubDate>
    <dc:creator>Perry_McGrew</dc:creator>
    <dc:date>2025-06-17T11:09:28Z</dc:date>
    <item>
      <title>P2P VPN Star Community - Link Selection Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251365#M49191</link>
      <description>&lt;P&gt;All our CP devices are R82 JHF 19.&amp;nbsp; &amp;nbsp;We have 7 CP 3200's deployed, each as a Star Community that are P2P VPN to our corporate Data Center 5800 HA Cluster.&lt;/P&gt;&lt;P&gt;I have been reading up on how to set these 3200's up as MEP to be able to failover to our Service Provider's DRaaS site where they use a Fortigate Firewall.&amp;nbsp; A whole other headache!&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have been using CP for close to 20 years. Just doing upgrades and appliance replacements as they reach EoL.&amp;nbsp; So I am looking at these VPN Star Communities settings and see the choice in Link Selection Mode.&amp;nbsp; Of course, all our CP3200's are set to Legacy vs Enhanced (Recommended) - where the "i bubble" states for better interoperability, redundancy, and granularity.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I am looking to make this eventual MEP configuration easy as possible and wondering if the Link Selection Mode needs to be changed or just should be regardless.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can I just change the CP3200 Link Selection setting to Enhanced and install policy or are there other settings that I should be aware of.&amp;nbsp; &amp;nbsp;I don't have a test CP3200 I can try and have not found any SK's on details with Link Selection Mode.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 17:33:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251365#M49191</guid>
      <dc:creator>Perry_McGrew</dc:creator>
      <dc:date>2025-06-16T17:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: P2P VPN Star Community - Link Selection Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251366#M49192</link>
      <description>&lt;P&gt;Hi Perry,&lt;/P&gt;
&lt;P&gt;That enhanced setting does exactly what it says, what you described. As far as MEP, thats more less the same as in previous versions. Personally, I would change the mode to enhanced and then enable MEP as required.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/MEP.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_SitetoSiteVPN_AdminGuide/Topics-VPNSG/MEP.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 18:02:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251366#M49192</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-16T18:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: P2P VPN Star Community - Link Selection Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251422#M49218</link>
      <description>&lt;P&gt;Andy,&lt;/P&gt;&lt;P&gt;Thanks for the reply.&amp;nbsp; &amp;nbsp;First we are R82 and I have read the R82 VPN Admin Guide.&amp;nbsp; There is only 1 external, internet facing connection on these CP3200s.&amp;nbsp; So I am trying to understand if there is any benefit to change from Legacy to Enhanced.&amp;nbsp; I am always wary about changing a setting like this and not "seeing" what other settings need to change.&lt;/P&gt;&lt;P&gt;As for MEP, pretty sure I will need Implicit MEP that I specify the Priority - our corporate 5800 HA would be "Primary" and the D/R site's Fortigate (interoperable device) would be "Backup".&amp;nbsp; The docs become confusing when discussing defining the VPN domain.&amp;nbsp; In D/R situation, our servers and Internet would be up at the D/R site.&amp;nbsp; On pg 203, Config Implicit MEP,&amp;nbsp; it implies the backup Gateway is a CP device...&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 11:09:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251422#M49218</guid>
      <dc:creator>Perry_McGrew</dc:creator>
      <dc:date>2025-06-17T11:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: P2P VPN Star Community - Link Selection Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251427#M49220</link>
      <description>&lt;P&gt;Is there any benefit? I would say better communication and less possibility of failures with clould and 3rd party vendors. As far as MEP, implicit is used if vpn domains are overlapping.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 11:39:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251427#M49220</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-17T11:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: P2P VPN Star Community - Link Selection Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251466#M49232</link>
      <description>&lt;P&gt;The Enhanced Link Selection allows for scenarios that are difficult to achieve with the Legacy options.&lt;BR /&gt;You have to explicitly configure it, though:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Link-Selection-Enhanced.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Link-Selection-Enhanced.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 17:55:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251466#M49232</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-17T17:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: P2P VPN Star Community - Link Selection Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251510#M49239</link>
      <description>&lt;P&gt;I posed the question to TAC and they responded with what I figured the answer after reading the R82 VPN Admin Guide.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"If your gateway has only a single interface connected to the Internet,&amp;nbsp;Enhanced Link Selection does not provide any significant benefit. "&lt;/P&gt;&lt;P&gt;So its back to unraveling how to set up Implicit MEP with a 3rd party Firewall as the Backup P2P VPN site.&amp;nbsp; .&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 10:31:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251510#M49239</guid>
      <dc:creator>Perry_McGrew</dc:creator>
      <dc:date>2025-06-18T10:31:06Z</dc:date>
    </item>
    <item>
      <title>Re: P2P VPN Star Community - Link Selection Mode</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251515#M49241</link>
      <description>&lt;P&gt;I agree with TAC, thats definitely true. I could be mistaken when I say this, but in my mind, MEP config should work regardless of how many external links are present.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 10:56:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/P2P-VPN-Star-Community-Link-Selection-Mode/m-p/251515#M49241</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-06-18T10:56:23Z</dc:date>
    </item>
  </channel>
</rss>

