<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Numbered VTIs between 2 centrally managed CheckPoint clusters in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Numbered-VTIs-between-2-centrally-managed-CheckPoint-clusters/m-p/58020#M11710</link>
    <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;I found some topics in this Community concerning VTIs, but all scenarios seem different to mine so I'm asking you guys for your insights.&lt;/P&gt;&lt;P&gt;We have 2 CheckPoint clusters, both centrally managed in the same SMS. One is Openserver R77.30, the other is a 1450 cluster R77.20.8x. In a normal situation, these sites communicate via MPLS. As a backup connection, we are required to configure an IPSEC site-to-site tunnel. To make failover (from MPLS to S2S) possible, I'm configuring VTI interfaces with routes with a higher metric.&lt;/P&gt;&lt;P&gt;I found some SKs about this (sk113735) and read "Configuring Numbered VTIs" in the Admin Guide but.&lt;/P&gt;&lt;P&gt;The Admin Guide describes how you create 1 VTI tunnel pair between the cluster and one gateway:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/34437.gif" border="0" alt="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/34437.gif" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;But&lt;/STRONG&gt;&lt;/U&gt; we need this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="tmpfig.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1855iA7BFCE3A73ED4AE7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tmpfig.jpg" alt="tmpfig.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) VTI pair between memberA1 and memberB1&lt;/P&gt;&lt;P&gt;2) VTI pair between memberA1 and memberB2&lt;/P&gt;&lt;P&gt;3) VTI pair between memberA2 and memberB1&lt;/P&gt;&lt;P&gt;4) VTI pair between memberA2 and memberB2&lt;/P&gt;&lt;P&gt;But this creates two tunnels, making it impossible to create working routing.&lt;/P&gt;&lt;P&gt;Or am I missing something?&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jul 2019 13:17:15 GMT</pubDate>
    <dc:creator>Philip_W</dc:creator>
    <dc:date>2019-07-11T13:17:15Z</dc:date>
    <item>
      <title>Numbered VTIs between 2 centrally managed CheckPoint clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Numbered-VTIs-between-2-centrally-managed-CheckPoint-clusters/m-p/58020#M11710</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;I found some topics in this Community concerning VTIs, but all scenarios seem different to mine so I'm asking you guys for your insights.&lt;/P&gt;&lt;P&gt;We have 2 CheckPoint clusters, both centrally managed in the same SMS. One is Openserver R77.30, the other is a 1450 cluster R77.20.8x. In a normal situation, these sites communicate via MPLS. As a backup connection, we are required to configure an IPSEC site-to-site tunnel. To make failover (from MPLS to S2S) possible, I'm configuring VTI interfaces with routes with a higher metric.&lt;/P&gt;&lt;P&gt;I found some SKs about this (sk113735) and read "Configuring Numbered VTIs" in the Admin Guide but.&lt;/P&gt;&lt;P&gt;The Admin Guide describes how you create 1 VTI tunnel pair between the cluster and one gateway:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/34437.gif" border="0" alt="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/34437.gif" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;But&lt;/STRONG&gt;&lt;/U&gt; we need this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="tmpfig.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/1855iA7BFCE3A73ED4AE7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tmpfig.jpg" alt="tmpfig.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) VTI pair between memberA1 and memberB1&lt;/P&gt;&lt;P&gt;2) VTI pair between memberA1 and memberB2&lt;/P&gt;&lt;P&gt;3) VTI pair between memberA2 and memberB1&lt;/P&gt;&lt;P&gt;4) VTI pair between memberA2 and memberB2&lt;/P&gt;&lt;P&gt;But this creates two tunnels, making it impossible to create working routing.&lt;/P&gt;&lt;P&gt;Or am I missing something?&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jul 2019 13:17:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Numbered-VTIs-between-2-centrally-managed-CheckPoint-clusters/m-p/58020#M11710</guid>
      <dc:creator>Philip_W</dc:creator>
      <dc:date>2019-07-11T13:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: Numbered VTIs between 2 centrally managed CheckPoint clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Numbered-VTIs-between-2-centrally-managed-CheckPoint-clusters/m-p/58079#M11725</link>
      <description>&lt;P&gt;I am puzzled a bit by your question: &lt;SPAN&gt;R77.30 could be a Load Sharing Cluster, the other is a 1450 cluster R77.20.8x that is only capable of HA Clustering,&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;but despite that, a HA cluster consisting of two nodes&amp;nbsp;has one external virtual cluster IP - so&amp;nbsp;you only need one tunnel between the two&amp;nbsp;external virtual cluster IPs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 08:03:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Numbered-VTIs-between-2-centrally-managed-CheckPoint-clusters/m-p/58079#M11725</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-07-12T08:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Numbered VTIs between 2 centrally managed CheckPoint clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Numbered-VTIs-between-2-centrally-managed-CheckPoint-clusters/m-p/58092#M11729</link>
      <description>&lt;P&gt;Hmmm, actually this is more a question of how to configure the VTI interface between clusters:&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://sc1.checkpoint.com/sc/SolutionsStatics/sk113735/11610050058.png" border="0" alt="" width="319" height="278" /&gt;&lt;/P&gt;&lt;P&gt;(screenshot from sk113735)&lt;/P&gt;&lt;P&gt;Cluster1 we have (example IPs)&lt;/P&gt;&lt;P&gt;member1 vti local ip 10.10.10.10, remote ip 20.20.20.1&lt;/P&gt;&lt;P&gt;member2 vti local ip 10.10.10.11, remote ip 20.20.20.1&lt;/P&gt;&lt;P&gt;cluster VIP: 10.10.10.1&lt;/P&gt;&lt;P&gt;Cluster2:&lt;/P&gt;&lt;P&gt;member1 vti local ip 20.20.20.20, remote ip 10.10.10.1&lt;/P&gt;&lt;P&gt;member2 vti local ip 20.20.20.21, remote ip 10.10.10.1&lt;/P&gt;&lt;P&gt;cluster VIP: 20.20.20.1&lt;/P&gt;&lt;P&gt;I couldn't get it working like this, so I was guessing this config is wrong.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 09:10:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Numbered-VTIs-between-2-centrally-managed-CheckPoint-clusters/m-p/58092#M11729</guid>
      <dc:creator>Philip_W</dc:creator>
      <dc:date>2019-07-12T09:10:03Z</dc:date>
    </item>
    <item>
      <title>Re: Numbered VTIs between 2 centrally managed CheckPoint clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Numbered-VTIs-between-2-centrally-managed-CheckPoint-clusters/m-p/58094#M11731</link>
      <description>&lt;P&gt;You have &amp;nbsp;Site to Site VPN Administration Guide R80.30 and on p.83&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;you see:&amp;nbsp;&lt;/SPAN&gt;Configuring VTIs in a Clustered Environment&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;- you&amp;nbsp;&lt;/SPAN&gt;only have to transfer the config to two clusters.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jul 2019 09:56:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Numbered-VTIs-between-2-centrally-managed-CheckPoint-clusters/m-p/58094#M11731</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-07-12T09:56:51Z</dc:date>
    </item>
  </channel>
</rss>

