<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route Based VPN (VTI) through Secondary ISP on Load Sharing Firewalls in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259947#M50981</link>
    <description>&lt;P&gt;Yep, that does work, used it before.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 15 Oct 2025 15:14:42 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-10-15T15:14:42Z</dc:date>
    <item>
      <title>Route Based VPN (VTI) through Secondary ISP on Load Sharing Firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259797#M50948</link>
      <description>&lt;P&gt;I have a customer who has an HA pair set to Load-Sharing mode and is on R81.20. A VTI configuration with a third-party that is utilizing Ubiquiti devices. The firewalls are set as Load-Sharing in ISP Redundancy with the VPN check box cleared. The customer wishes to know the following.&lt;BR /&gt;&lt;BR /&gt;How do they configure their route-based VPN to specifically use the secondary ISP connection? Their primary ISP has been having port flapping issues which is affecting the connection from the remote location's device to their network. Hence why they wish to do this. Any recommendations or things I should look out for? Any information would be appreciated.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 21:46:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259797#M50948</guid>
      <dc:creator>Sbolton</dc:creator>
      <dc:date>2025-10-13T21:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN (VTI) through Secondary ISP on Load Sharing Firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259799#M50950</link>
      <description>&lt;P&gt;Sounds like they need to make sure secondary ISP link works right. If 1st fails, does other one take over?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 23:46:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259799#M50950</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-13T23:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN (VTI) through Secondary ISP on Load Sharing Firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259800#M50951</link>
      <description>&lt;P&gt;How is your "link selection" configured currently, believe there were some enhancements with this under R82 per:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Link-Selection-Enhanced.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/Link-Selection-Enhanced.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Oct 2025 00:50:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259800#M50951</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-10-14T00:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN (VTI) through Secondary ISP on Load Sharing Firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259922#M50973</link>
      <description>&lt;P&gt;The issue seems to be a hop along the path through one ISP compared to the other. It's pretty consistent, so they want to make the secondary connection the primary JUST for this vpn tunnel.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 13:04:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259922#M50973</guid>
      <dc:creator>Sbolton</dc:creator>
      <dc:date>2025-10-15T13:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN (VTI) through Secondary ISP on Load Sharing Firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259925#M50974</link>
      <description>&lt;P&gt;You're right, that R82 enhanced link section is exactly what we would need for this too. I'll bring this up to the customer as they weren't planning on moving to R82 until December. I'll send this over to them to review. Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 13:05:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259925#M50974</guid>
      <dc:creator>Sbolton</dc:creator>
      <dc:date>2025-10-15T13:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN (VTI) through Secondary ISP on Load Sharing Firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259930#M50978</link>
      <description>&lt;P&gt;Until you go to R82, for R80.20 and higher, you can use the BestRoutingSenderIP config as noted in&amp;nbsp;&lt;SPAN&gt;sk108600, Scenario 2. &amp;nbsp;Since R80.30, IKEv2 is also supported:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108600" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108600&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I use this regularly for several customers with multiple upstream next-hops. &amp;nbsp;You'll need a static route on the gateway for the remote peer to exit the interface you want towards the desired next hop.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After this is set, the IKE ID for 3rd party VPN and PSK will adjust accordingly.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 13:37:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259930#M50978</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-10-15T13:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN (VTI) through Secondary ISP on Load Sharing Firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259947#M50981</link>
      <description>&lt;P&gt;Yep, that does work, used it before.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 15:14:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259947#M50981</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-15T15:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN (VTI) through Secondary ISP on Load Sharing Firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259950#M50982</link>
      <description>&lt;P&gt;Would these changes revert after an upgrade to R82?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 15:18:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259950#M50982</guid>
      <dc:creator>Sbolton</dc:creator>
      <dc:date>2025-10-15T15:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN (VTI) through Secondary ISP on Load Sharing Firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259987#M50990</link>
      <description>&lt;P&gt;The changes are in the HKLM_registry.data file, which would not be carried over for upgrades (in-place or otherwise). &amp;nbsp;They will remain in place for Jumbo HFA updates, however.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Oct 2025 18:43:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/259987#M50990</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-10-15T18:43:14Z</dc:date>
    </item>
    <item>
      <title>Re: Route Based VPN (VTI) through Secondary ISP on Load Sharing Firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/260017#M50999</link>
      <description>&lt;P&gt;I would definitely back up the file, but&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/694"&gt;@Duane_Toler&lt;/a&gt;&amp;nbsp;is absolutely correct.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Oct 2025 06:07:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-Based-VPN-VTI-through-Secondary-ISP-on-Load-Sharing/m-p/260017#M50999</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-16T06:07:17Z</dc:date>
    </item>
  </channel>
</rss>

