<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: About site-to-site VPN outgoing route selection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265715#M52331</link>
    <description>&lt;P&gt;This is a great point to mention, thank you Amir. So when doing VPN orchestration between Checkpoint Gateways which are centrally managed and which all have and SD-WAN license, SD-WAN ignores all Link selection settings for those relevant gateways.&lt;/P&gt;&lt;P&gt;However, if one of those Checkpoint gateways has a VPN tunnel to another centrally Managed Checkpoint Gateway without SD-WAN license, or to a 3rd party gateway, I imagine that Link selection takes effect. Is this correct?&lt;/P&gt;</description>
    <pubDate>Thu, 18 Dec 2025 18:39:58 GMT</pubDate>
    <dc:creator>Steven_Sultana</dc:creator>
    <dc:date>2025-12-18T18:39:58Z</dc:date>
    <item>
      <title>About site-to-site VPN outgoing route selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265603#M52323</link>
      <description>&lt;P&gt;This is more of an academic question, rather than me having an issue I would like to solve.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There are 2 interesting settings in the "outgoing route selection" section of the "IPSec VPN &amp;gt; Link Selection" panel:&lt;/P&gt;&lt;P&gt;1. Setup: When responding to a remotely initiated tunnel, determine the outgoing interfacing using:&lt;/P&gt;&lt;P&gt;1.a. Use outgoing traffic configuration&lt;/P&gt;&lt;P&gt;1.b. Reply from the same interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Source IP address settings: When initiating a tunnel user the following IP address as the source IP of outgoing packets:&lt;/P&gt;&lt;P&gt;2.a. Automatic (derived from method of IP selection be remote peer)&lt;/P&gt;&lt;P&gt;2.b. Selected address from topology table&lt;/P&gt;&lt;P&gt;2.c. IP address of chosen interface&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my opinion, the answer to these questions should always be 1.b. (it's always polite to face the person you are speaking to &lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;) and 2.c. (or else the next hop might drop your packets, since the packets do not belong to the next-hop network).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is my assumption wrong?&lt;/P&gt;&lt;P&gt;What are the scenarios when these configurations are counter-productive?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 21:11:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265603#M52323</guid>
      <dc:creator>Steven_Sultana</dc:creator>
      <dc:date>2025-12-17T21:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: About site-to-site VPN outgoing route selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265605#M52324</link>
      <description>&lt;P&gt;What’s about use cases like multiple external interfaces, using SD-WAN or pbr? Does the assumption still apply on all ?&lt;/P&gt;
&lt;P&gt;Perhaps someone has the time and inclination to run through the scenarios; I have to go to bed. Two more working days, then it's holiday time.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 21:47:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265605#M52324</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2025-12-17T21:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: About site-to-site VPN outgoing route selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265606#M52325</link>
      <description>&lt;P&gt;Holiday time is when these weird questions come to my mind!&lt;/P&gt;&lt;P&gt;But good point - main use case is multiple external interfaces, probably with multiple 3rd party (or tbf even managed CP) gateways which may need to connect to different external interfaces for a variety of reasons.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Dec 2025 21:59:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265606#M52325</guid>
      <dc:creator>Steven_Sultana</dc:creator>
      <dc:date>2025-12-17T21:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: About site-to-site VPN outgoing route selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265609#M52326</link>
      <description>&lt;P&gt;I just checked one of our clients that uses ISPR and the setting is set to link redundancy mode-&amp;gt; HA, then you choose main link.&lt;/P&gt;
&lt;P&gt;This is what help section indicates:&lt;/P&gt;
&lt;P&gt;Outgoing Route Selection &lt;BR /&gt;◦When Initiating a Tunnel &lt;span class="lia-unicode-emoji" title=":black_medium_small_square:"&gt;◾&lt;/span&gt;Operating system routing table - Using this method, the routing table is consulted for the link with the lowest metric (highest priority) to send traffic.&lt;BR /&gt;&lt;span class="lia-unicode-emoji" title=":black_medium_small_square:"&gt;◾&lt;/span&gt;Route based probing - This method also consults the routing table for the link with the lowest metric. However, before choosing a link to send traffic, all routing possibilities are examined to check that the link is active. The gateway then selects the best match (highest prefix length) active route with the lowest metric, and hence the highest priority. This method is recommended when there is more than one external interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Automatic (derived from the method of IP selection by remote peer) - The source IP address of outgoing traffic is derived from the method selected in the IP Selection by Remote Peer section.&lt;BR /&gt;◦If Main address or Selected address from topology table are selected in the IP Selection by Remote Peer section, then the source IP when initiating a VPN tunnel is the IP specified for that method.&lt;BR /&gt;◦If Calculate IP based on network topology, Statically NATed IP, Use DNS resolving or Use a probing method is chosen in the IP Selection by Remote Peer section, then the source IP when initiating a VPN tunnel is the IP address of the chosen outgoing interface.&lt;BR /&gt;◦Manual:&lt;BR /&gt;◦Main IP address - The source IP is derived from the General Properties page of the gateway.&lt;BR /&gt;◦Selected address from topology table - The chosen IP from the drop down menu becomes the source IP.&lt;BR /&gt;◦IP address of chosen interface - The source IP is the same IP of the interface where the traffic is being routed through.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2025 00:55:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265609#M52326</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-12-18T00:55:58Z</dc:date>
    </item>
    <item>
      <title>Re: About site-to-site VPN outgoing route selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265615#M52327</link>
      <description>&lt;P&gt;Quantum SD-WAN ignores all Link selection settings&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2025 07:40:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265615#M52327</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2025-12-18T07:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: About site-to-site VPN outgoing route selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265715#M52331</link>
      <description>&lt;P&gt;This is a great point to mention, thank you Amir. So when doing VPN orchestration between Checkpoint Gateways which are centrally managed and which all have and SD-WAN license, SD-WAN ignores all Link selection settings for those relevant gateways.&lt;/P&gt;&lt;P&gt;However, if one of those Checkpoint gateways has a VPN tunnel to another centrally Managed Checkpoint Gateway without SD-WAN license, or to a 3rd party gateway, I imagine that Link selection takes effect. Is this correct?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2025 18:39:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265715#M52331</guid>
      <dc:creator>Steven_Sultana</dc:creator>
      <dc:date>2025-12-18T18:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: About site-to-site VPN outgoing route selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265720#M52333</link>
      <description>&lt;P&gt;Correct.&lt;BR /&gt;*it's less a matter of license, but if SD-WAN policy is installed on the gateway.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2025 18:54:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265720#M52333</guid>
      <dc:creator>AmirArama</dc:creator>
      <dc:date>2025-12-18T18:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: About site-to-site VPN outgoing route selection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265744#M52336</link>
      <description>&lt;P&gt;Thank you Amir for the clarification! Yes, "policy" is more precise than "license" in this case.&lt;/P&gt;&lt;P&gt;And thank you Andy for the reference to Docs and for sharing your experience.&lt;/P&gt;&lt;P&gt;I'm very curious to meet someone who had 1.b or 2.c and had to move away from them due to issues being caused "in the wild."&lt;/P&gt;</description>
      <pubDate>Thu, 18 Dec 2025 22:40:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/About-site-to-site-VPN-outgoing-route-selection/m-p/265744#M52336</guid>
      <dc:creator>Steven_Sultana</dc:creator>
      <dc:date>2025-12-18T22:40:20Z</dc:date>
    </item>
  </channel>
</rss>

