<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How do I achieve failover with below topology and requirement in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/How-do-I-achieve-failover-with-below-topology-and-requirement/m-p/125804#M23180</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We currently have R1 and R2&amp;nbsp; router. Both have reachability to 10.100.0.0/16 subnet. However on L3 switch HO it does not support dynamic protocols and I need to achieve failover or redundancy for 10.100.0.0/16 originating from 172.31.21.0/24&lt;/P&gt;&lt;P&gt;Primarily traffic is routed to 10.11.12.2 for 10.100.0.0/16 [subnet specific route] and R1 has eBGP enabled with remote L3. Or my default route is pointed to 10.44.44.2. We&amp;nbsp; wanted to ensure lets suppose if my connectivity between 192.168.15.1 and 2 fails [which is a MPLS link] I have a Site-site tunnel configured as well between R2 and remote L3 which is through Internet and VTI again those have BGP peering enabled for 10.100.0.0/16&lt;/P&gt;&lt;P&gt;Any idea how can I achive failover here? I am planning to replace those R1 and R2 by Check Point 6000 devices and planning to use BGP however I am stuck in this failover scenario&lt;/P&gt;&lt;P&gt;One possibility I was thinking about joining R1 and R2 and can configure bgp there? or route redistribution? Pls help&lt;/P&gt;</description>
    <pubDate>Thu, 05 Aug 2021 18:17:23 GMT</pubDate>
    <dc:creator>Blason_R</dc:creator>
    <dc:date>2021-08-05T18:17:23Z</dc:date>
    <item>
      <title>How do I achieve failover with below topology and requirement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-do-I-achieve-failover-with-below-topology-and-requirement/m-p/125804#M23180</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We currently have R1 and R2&amp;nbsp; router. Both have reachability to 10.100.0.0/16 subnet. However on L3 switch HO it does not support dynamic protocols and I need to achieve failover or redundancy for 10.100.0.0/16 originating from 172.31.21.0/24&lt;/P&gt;&lt;P&gt;Primarily traffic is routed to 10.11.12.2 for 10.100.0.0/16 [subnet specific route] and R1 has eBGP enabled with remote L3. Or my default route is pointed to 10.44.44.2. We&amp;nbsp; wanted to ensure lets suppose if my connectivity between 192.168.15.1 and 2 fails [which is a MPLS link] I have a Site-site tunnel configured as well between R2 and remote L3 which is through Internet and VTI again those have BGP peering enabled for 10.100.0.0/16&lt;/P&gt;&lt;P&gt;Any idea how can I achive failover here? I am planning to replace those R1 and R2 by Check Point 6000 devices and planning to use BGP however I am stuck in this failover scenario&lt;/P&gt;&lt;P&gt;One possibility I was thinking about joining R1 and R2 and can configure bgp there? or route redistribution? Pls help&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 18:17:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-do-I-achieve-failover-with-below-topology-and-requirement/m-p/125804#M23180</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-08-05T18:17:23Z</dc:date>
    </item>
    <item>
      <title>Re: How do I achieve failover with below topology and requirement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-do-I-achieve-failover-with-below-topology-and-requirement/m-p/125810#M23181</link>
      <description>&lt;P&gt;Just to make sure I get this right, so you are replacing R1 and R2 with CP devices and want to ensure that there is failover scenario in case of any routing problems? If so, yes, BGP would make most sense...or did I misunderstand something?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 20:00:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-do-I-achieve-failover-with-below-topology-and-requirement/m-p/125810#M23181</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-08-05T20:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do I achieve failover with below topology and requirement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-do-I-achieve-failover-with-below-topology-and-requirement/m-p/125833#M23187</link>
      <description>&lt;P&gt;This is correct. I'll be replacing those with 6600 appliances. Both are separate firewall and being managed by same management server. I can configure the eBGP going to 10.100/16 on both of those. However wanted to ensure a redundancy for 10.100/16 as primary path would be through R1(Firewall1) and if that link fails how do I automatically divert traffic to through R2?&lt;/P&gt;&lt;P&gt;What exact changes needed between R1 &amp;amp; r2 (accordingly on Firewall1 and Firewall2)&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 02:23:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-do-I-achieve-failover-with-below-topology-and-requirement/m-p/125833#M23187</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-08-06T02:23:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do I achieve failover with below topology and requirement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-do-I-achieve-failover-with-below-topology-and-requirement/m-p/125834#M23188</link>
      <description>&lt;P&gt;I guess I need to configure iBGP between Firewall1 and 2 and redistribute routes learned from ebgp to ibgp?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 03:20:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-do-I-achieve-failover-with-below-topology-and-requirement/m-p/125834#M23188</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-08-06T03:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: How do I achieve failover with below topology and requirement</title>
      <link>https://community.checkpoint.com/t5/General-Topics/How-do-I-achieve-failover-with-below-topology-and-requirement/m-p/125840#M23189</link>
      <description>&lt;P&gt;OK - Finally I resolved with lot of R&amp;amp;D. However my topology assumption was wrong since AS in global to router or firewall and I was assuming router or firewall is part of Two AS.&lt;/P&gt;&lt;P&gt;I had to configure ebgp between R1-R2 and given higher weightage to R2 path&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 04:12:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/How-do-I-achieve-failover-with-below-topology-and-requirement/m-p/125840#M23189</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2021-08-06T04:12:10Z</dc:date>
    </item>
  </channel>
</rss>

