<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Route-based VPN on virtual Systems in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/98219#M9528</link>
    <description>&lt;P&gt;R81 will support this for VSX when released.&lt;/P&gt;</description>
    <pubDate>Mon, 05 Oct 2020 13:49:25 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2020-10-05T13:49:25Z</dc:date>
    <item>
      <title>Route-based VPN on virtual Systems</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/65597#M9524</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we create route-based VPNs on virtual systems? If so, he configuration should be done under the tenant VSX?&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 18:41:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/65597#M9524</guid>
      <dc:creator>Antonio_M</dc:creator>
      <dc:date>2019-10-22T18:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN on virtual Systems</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/65617#M9525</link>
      <description>Route-Based VPNs require VTIs, which are not currently supported on VSX.</description>
      <pubDate>Wed, 23 Oct 2019 03:51:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/65617#M9525</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-23T03:51:46Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN on virtual Systems</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/65626#M9526</link>
      <description>&lt;P&gt;Thank you PhoneBoy!&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 07:20:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/65626#M9526</guid>
      <dc:creator>Antonio_M</dc:creator>
      <dc:date>2019-10-23T07:20:38Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN on virtual Systems</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/98201#M9527</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Does VSX support the VTIs now? I mean can we configure the Route Based VPNs in VSX now?&lt;/P&gt;&lt;P&gt;In case if we need to setup a VPN between AWS or Azure in Virtual System how can we configure it?&lt;/P&gt;&lt;P&gt;Any suggestions? Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 09:49:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/98201#M9527</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2020-10-05T09:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN on virtual Systems</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/98219#M9528</link>
      <description>&lt;P&gt;R81 will support this for VSX when released.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Oct 2020 13:49:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/98219#M9528</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-10-05T13:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN on virtual Systems</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/150462#M24422</link>
      <description>&lt;P&gt;sk113840 - How to configure IPsec VPN (non-VTI) tunnel between Check Point Security Gateway and Amazon Web Services VPC using static routes says:&lt;/P&gt;&lt;P&gt;This article describes how to create a single VPN connection between Check Point and Amazon Web Services and is intended to be used in instances where VTIs are not permitted, such as the 61000 platform or VSX.&lt;/P&gt;&lt;P&gt;Keep in mind that VTI is important for redundancy and flexibility with AWS hosting. As the 61000 platform and VSX do not support VTIs, a single working tunnel can be created using this method, but is not a recommended configuration. Two separate tunnels will need to be created to Amazon Web Services, and any failover between the two tunnels must be done manually.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 04:17:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/150462#M24422</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2022-06-09T04:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN on virtual Systems</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/150464#M24423</link>
      <description>&lt;P&gt;Hi Paul,&lt;/P&gt;
&lt;P&gt;This limitation for VSX was addressed starting R81 per&amp;nbsp;&lt;SPAN&gt;sk79700.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 06:01:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/150464#M24423</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-06-09T06:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN on virtual Systems</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/150470#M24425</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;I'm aware that it's resolved in R81, I was replying to&amp;nbsp; Sanjay_S who was asking how to configure AWS VPN connectivity on older versions of VSX without support for VTIs - in case someone else had the same question.&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jun 2022 07:24:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/150470#M24425</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2022-06-09T07:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN on virtual Systems</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/154691#M26267</link>
      <description>&lt;P&gt;Except that with further investigation:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The vsx_provisioning_tool command for adding a VTI does not appear to support setting the MTU which is vastly preferable to trying to configure VPN MSS clamping.&lt;/LI&gt;&lt;LI&gt;There's no mechanism for routes on VSX to use ping tracking. Which means resilient connectivity to AWS would require BGP.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;All the more reason to avoid deploying VSX!&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 02:02:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/154691#M26267</guid>
      <dc:creator>Paul_Hagyard</dc:creator>
      <dc:date>2022-08-08T02:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: Route-based VPN on virtual Systems</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/154695#M26268</link>
      <description>&lt;P&gt;AWS recommends BGP for the VPN where available.&lt;/P&gt;
&lt;P&gt;MSS clamping works just fine, architecturally it probably has fewer draw backs if your VS is dedicated to the VPN i.e.&lt;/P&gt;
&lt;P&gt;Set fw_clamp_vpn_mss=1 to $FWDIR/boot/modules/fwkern.conf&lt;BR /&gt;Set sim_clamp_vpn_mss=1 to $PPKDIR/conf/simkern.conf (new file)&lt;BR /&gt;Set mss_value to 13XX for &amp;lt;TRANSIT_IF_NAME&amp;gt; in guidbedit for VS&lt;BR /&gt;Set MTU to 14XX on &amp;lt;TRANSIT_IF_NAME&amp;gt; for VS in SmartConsole&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 04:18:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Route-based-VPN-on-virtual-Systems/m-p/154695#M26268</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-08-08T04:18:56Z</dc:date>
    </item>
  </channel>
</rss>

