<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route Based VPN Tunnel on VSX (Virtual System) in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259640#M50921</link>
    <description>&lt;P&gt;SmartConsole won't allow you to configure it under classic VSX per sk79700.&lt;/P&gt;
&lt;P&gt;"Multiple Static Routes with different priorities to the same destination"&lt;/P&gt;</description>
    <pubDate>Fri, 10 Oct 2025 12:39:30 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2025-10-10T12:39:30Z</dc:date>
    <item>
      <title>Route Based VPN Tunnel on VSX (Virtual System)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259634#M50917</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We want to configure a route-based VPN tunnel. Below are the environment details:&lt;/P&gt;&lt;P&gt;* Local Gateway- checkpoint Virtual System Firewall&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Peer gateways:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Site-A: Third party Firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; Site-B: Third party Firewall&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;* Peer Encryption Domain: common (172.16.1.0/24), behind both location's Firewalls.&lt;/P&gt;&lt;P&gt;* Routing on Local Gateway: Static&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As peer encryption domain is common (172.16.1.0/24) which is to be access from our side through the IPSec.&lt;/P&gt;&lt;P&gt;&amp;nbsp;We are planning to implement route-based VPN with both the locations, so that if primary tunnel with Site-A goes down then same Sunbnet_172.16.1.0/24 should be accessible through Site-B's tunnels.&lt;/P&gt;&lt;P&gt;We want to use static routing for this route-based VPN setup.&lt;/P&gt;&lt;P&gt;But we are not able to find route minoring option for VTY interface, as in standard environment (without vsx) we can enable next hop monitoring while configure the static route.&lt;/P&gt;&lt;P&gt;So, looking a solution for tunnel failover with static routing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 11:37:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259634#M50917</guid>
      <dc:creator>VishnuK</dc:creator>
      <dc:date>2025-10-10T11:37:39Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN Tunnel on VSX (Virtual System)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259635#M50918</link>
      <description>&lt;P&gt;To my knowledge route based VPNs for VSX are only supported with dynamic routing e.g. BGP.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 11:55:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259635#M50918</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-10-10T11:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN Tunnel on VSX (Virtual System)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259636#M50919</link>
      <description>&lt;P&gt;you need dynamic routing for this like bgp&amp;nbsp;&lt;/P&gt;
&lt;OL class="IaGLZe VimKh" data-processed="true"&gt;
&lt;LI data-hveid="CAMQAg" data-processed="true"&gt;&lt;SPAN class="T286Pc" data-sfc-cp="" data-processed="true"&gt;&lt;STRONG class="Yjhzub" data-processed="true"&gt;Dynamic Routing:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;This infrastructure enables dynamic routing protocols (like OSPF or BGP) to exchange routing information directly with a routing daemon on the other end of the tunnel, making it appear as a single hop.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN class="T286Pc" data-sfc-cp="" data-processed="true"&gt;Check also policy based routing, is now also supported on vsx&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="T286Pc" data-sfc-cp="" data-processed="true"&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk167135" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk167135&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 11:57:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259636#M50919</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-10-10T11:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN Tunnel on VSX (Virtual System)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259639#M50920</link>
      <description>&lt;P&gt;1. Does it mean we can't achieve it, using route monitoring with Static routing?&lt;/P&gt;&lt;P&gt;2. PBR can be used into this case for tunnel failover?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 12:32:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259639#M50920</guid>
      <dc:creator>VishnuK</dc:creator>
      <dc:date>2025-10-10T12:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN Tunnel on VSX (Virtual System)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259640#M50921</link>
      <description>&lt;P&gt;SmartConsole won't allow you to configure it under classic VSX per sk79700.&lt;/P&gt;
&lt;P&gt;"Multiple Static Routes with different priorities to the same destination"&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 12:39:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259640#M50921</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-10-10T12:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN Tunnel on VSX (Virtual System)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259644#M50922</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/106357"&gt;@VishnuK&lt;/a&gt;&amp;nbsp;what do you want to achieve? You need redundancy for your VPN ? Why route based VPN?&amp;nbsp;&lt;BR /&gt;I believe you can use the domain based VPN with two third party gateways at the remote site. Redundancy via MEP (MultipleEntryPoint) and using DPD (DeadPeerDetection) to probe the remote gateways availability.&amp;nbsp;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk10860&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;scenario 8&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 12:53:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259644#M50922</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2025-10-10T12:53:32Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN Tunnel on VSX (Virtual System)</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259766#M50940</link>
      <description>&lt;P&gt;Hi Wolfgang,&lt;/P&gt;&lt;P&gt;Yes, we want we need redundancy for IPSec.&amp;nbsp; MEP is applicable here? I am suspecting that, considering below points:&lt;/P&gt;&lt;P&gt;* We have the control of Local firewall only&lt;/P&gt;&lt;P&gt;* Traffic direction is outbound (Local to 3rd Party)&lt;/P&gt;&lt;P&gt;* Peer Firewalls are not checkpoint.&lt;/P&gt;&lt;P&gt;As per my understanding MEP can be configured only for incoming traffic. Please correct me, if i am wrong.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 09:41:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-Tunnel-on-VSX-Virtual-System/m-p/259766#M50940</guid>
      <dc:creator>VishnuK</dc:creator>
      <dc:date>2025-10-13T09:41:13Z</dc:date>
    </item>
  </channel>
</rss>

