<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I setup a primary and backup S2S VPN tunnels in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/76185#M15464</link>
    <description>While probing is likely to fail using CP proprietary RDP with 3rd party devices, there is some value in link selection. Rather than relying on RDP to find the path, you could rely on the 3rd party device decision as discussed here as well:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-Link-Selection/m-p/10729/highlight/true#M1542" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-Link-Selection/m-p/10729/highlight/true#M1542&lt;/A&gt;&lt;BR /&gt;If you can get the remote peer to establish the session first you should be golden using "reply from same interface".</description>
    <pubDate>Mon, 24 Feb 2020 12:00:40 GMT</pubDate>
    <dc:creator>Albert_Wilkes</dc:creator>
    <dc:date>2020-02-24T12:00:40Z</dc:date>
    <item>
      <title>How can I setup a primary and backup S2S VPN tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23625#M4689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Scenario:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;1 local Checkpoint R80.10 gateway cluster (site L1)&amp;nbsp;need to establish a primary site to site tunnel to&amp;nbsp;remote Fortinet gateway (site R1) having&amp;nbsp;HostA and HostB. A secondary remote site (R2)&amp;nbsp;exists housing HostC sync'ed from R1 HostA. There is "link" between R1 and R2 managed by the Vendor. L1 gateway needs to have backup/secondary site to site tunnel to R2 in the event R1 gateway is not available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users behind L1 access HostA and HostB through primary tunnel to R1. Users behind L1 access HostC&amp;nbsp;at R2 via primary tunnel to R1 and then link to R2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question&lt;/STRONG&gt;: For us to have automatic failover of traffic destined to HostA, HostB and HostC to&amp;nbsp;flow over&amp;nbsp;the secondary tunnel, would configuring&amp;nbsp; route statements on the gateway's OS with different priority work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;hostA&amp;nbsp; nexthop gw X&amp;nbsp;&amp;nbsp;&amp;nbsp; priority1&amp;nbsp; (flows over tunnel to R1)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hostA&amp;nbsp; nexthop gw Y&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;priority2&amp;nbsp; (flows over tunnel to R2)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would the gw IP be the actual Fortinet IP or would it be an IP within the tunnel?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: This setup would be extended to another local site (L2) to provide redundancy in the event of losing L1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2018 19:49:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23625#M4689</guid>
      <dc:creator>Jacques_Spelier</dc:creator>
      <dc:date>2018-01-16T19:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: How can I setup a primary and backup S2S VPN tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23626#M4690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want the routing table to determine priority, you need to configure the VPN with VTIs.&lt;/P&gt;&lt;P&gt;See the Route-Based VPN section of:&amp;nbsp;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/html_frameset.htm" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/html_frameset.htm"&gt;Site to Site VPN R80.10 - Part of Check Point Infinity&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 05:13:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23626#M4690</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-01-17T05:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: How can I setup a primary and backup S2S VPN tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23627#M4691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could also check if &lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/html_frameset.htm"&gt;Domain Based VPN&lt;/A&gt; with Link Selection and Probing might be a solution for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/62109_pastedImage_1.png" style="width: 620px; height: 586px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 07:47:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23627#M4691</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-01-17T07:47:11Z</dc:date>
    </item>
    <item>
      <title>Re: How can I setup a primary and backup S2S VPN tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23628#M4692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Danny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think Link Selection with Probing will not work in this case since there is a Fortinet device on the remote end.&lt;/P&gt;&lt;P&gt;This setting only work when you have another Check Point devices managed by the same security management, so at the policy install you are telling them to use RDP Probing to test the addresses on the list.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dameon's recommendation of using Route Based VPN will be more adequate to this scenario. Since Fortinet supports this technology, the most adequate approach is use Numbered VTI. This way all the encryption is made according to the routing table and can define different priorities for the traffic. Also there is the advantage he's using R80.10, so Route Based VPN works without disabling CoreXL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 13:06:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23628#M4692</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-01-17T13:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: How can I setup a primary and backup S2S VPN tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23629#M4693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are absolutely right as Link Selection Probing relies on a Check Point proprietary protocol. I was just giving a more open answer to others reading this sometimes being in a similar situation. In cases where you are limited to Domain Based VPN (e.g. VSX users - &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110519#VSX"&gt;sk110519&lt;/A&gt;, &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk30975"&gt;sk30975&lt;/A&gt;, &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk79700"&gt;sk79700&lt;/A&gt;) your only choice is to evaluate and go with Link Selection. If your VPN partner doesn't have a Check Point solution you might need to set up a dedicated Non-VSX VPN Gatetway and use VTIs or please your VPN partner to use Check Point &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Jan 2018 14:47:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23629#M4693</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-01-17T14:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: How can I setup a primary and backup S2S VPN tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23630#M4694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks everyone for the useful feedback. Any concerns with the same local gateways&amp;nbsp;terminating other different VPNs in a different configuration? more than 3 communities,some mesh, some star.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Jan 2018 15:32:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23630#M4694</guid>
      <dc:creator>Jacques_Spelier</dc:creator>
      <dc:date>2018-01-18T15:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: How can I setup a primary and backup S2S VPN tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23631#M4695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can i configure both numbered and unnumbered VTI on the same box?&lt;/P&gt;&lt;P&gt;unnumbered with ospf and numbered with bgp?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to Note: according to R80.10 admin guide it says 1-99 VTI, but when checked it can scale up to&amp;nbsp;&amp;nbsp;0..32768.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2018 17:42:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23631#M4695</guid>
      <dc:creator>VENKAT_S_P</dc:creator>
      <dc:date>2018-01-23T17:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: How can I setup a primary and backup S2S VPN tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23632#M4696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems like the configs shown under "Configuring member_GWA1" needs&amp;nbsp;correction.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/html_frameset.htm" title="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/html_frameset.htm"&gt;Site to Site VPN R80.10 Administration Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;================&lt;/P&gt;&lt;P&gt;&lt;CODE class="" style="background-color: inherit; padding: 0pt;"&gt;--------- Add vt-GWb &lt;/CODE&gt;&lt;/P&gt;&lt;PRE class="" style="color: #000000; background-color: inherit; text-decoration: none; font-size: 12px; margin: 6pt; padding: 0pt;"&gt;&lt;CODE class="" style="background-color: inherit; padding: 0pt;"&gt;VPN shell:[/] &amp;gt; /interface/add/numbered 10.0.1.&lt;STRONG&gt;11&lt;/STRONG&gt; 10.0.0.2 GWb &lt;/CODE&gt;&lt;/PRE&gt;&lt;PRE class="" style="color: #000000; background-color: inherit; text-decoration: none; font-size: 12px; margin: 6pt; padding: 0pt;"&gt;&lt;CODE class="" style="background-color: inherit; padding: 0pt;"&gt;Interface 'vt-GWb' was added successfully to the system&lt;/CODE&gt;&lt;/PRE&gt;&lt;PRE class="" style="color: #000000; background-color: inherit; text-decoration: none; font-size: 12px; margin: 6pt; padding: 0pt;"&gt;&lt;CODE class="" style="background-color: inherit; padding: 0pt;"&gt;--------- Add vt-GWc&lt;/CODE&gt;&lt;/PRE&gt;&lt;PRE class="" style="color: #000000; background-color: inherit; text-decoration: none; font-size: 12px; margin: 6pt; padding: 0pt;"&gt;&lt;CODE class="" style="background-color: inherit; padding: 0pt;"&gt;VPN shell:[/] &amp;gt; /interface/add/numbered 10.0.1.&lt;STRONG&gt;21&lt;/STRONG&gt; 10.0.0.3 GWc&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/CODE&gt;&lt;/PRE&gt;&lt;PRE class="" style="color: #000000; background-color: inherit; text-decoration: none; font-size: 12px; margin: 6pt; padding: 0pt;"&gt;&lt;CODE class="" style="background-color: inherit; padding: 0pt;"&gt;Interface 'vt-GWc' was added successfully to the system&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;================&lt;/P&gt;&lt;P&gt;I checked one for R77 and found the same.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://sc1.checkpoint.com/documents/R77/CP_R77_VPN_AdminGuide/13824.htm" title="https://sc1.checkpoint.com/documents/R77/CP_R77_VPN_AdminGuide/13824.htm"&gt;Route Based VPN&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2018 19:17:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/23632#M4696</guid>
      <dc:creator>VENKAT_S_P</dc:creator>
      <dc:date>2018-01-23T19:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: How can I setup a primary and backup S2S VPN tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/76185#M15464</link>
      <description>While probing is likely to fail using CP proprietary RDP with 3rd party devices, there is some value in link selection. Rather than relying on RDP to find the path, you could rely on the 3rd party device decision as discussed here as well:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-Link-Selection/m-p/10729/highlight/true#M1542" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/IPSec-VPN-Link-Selection/m-p/10729/highlight/true#M1542&lt;/A&gt;&lt;BR /&gt;If you can get the remote peer to establish the session first you should be golden using "reply from same interface".</description>
      <pubDate>Mon, 24 Feb 2020 12:00:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-can-I-setup-a-primary-and-backup-S2S-VPN-tunnels/m-p/76185#M15464</guid>
      <dc:creator>Albert_Wilkes</dc:creator>
      <dc:date>2020-02-24T12:00:40Z</dc:date>
    </item>
  </channel>
</rss>

