<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Redundant VPN over BGP in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Redundant-VPN-over-BGP/m-p/198087#M33166</link>
    <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;I have carried out a laboratory to test redundant VPNs over BGP, I share with you the topology of my environment and the configurations on the checkpoint side, I hope it helps you.&lt;/P&gt;&lt;P&gt;LAB.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LAB_TOPLGY.png" style="width: 520px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23224i1EB70BD687FDE47C/image-dimensions/520x356?v=v2" width="520" height="356" role="button" title="LAB_TOPLGY.png" alt="LAB_TOPLGY.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;ASN1 and ASN2 are the remote gateways with which I will set up the VPNs.&lt;/P&gt;&lt;P&gt;&lt;U&gt;OBJECTIVE:&lt;/U&gt; The "HOST_LOCAL" connects with the "HOST_REMOTE" through a VPN over BGP with ASN1, if this VPN goes down, there will be a VPN over BGP with ASN2 to reach the "HOST_REMOTE" again, guaranteeing that connectivity is not lost between both hosts using VPNs.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Configuration at the checkpoint.&lt;/U&gt;&lt;/P&gt;&lt;P&gt;At the GAIA level, we create a VPN-tunnel interface, where we define the tunnel ID, in this case 1, and we will place the peering IPs that we have defined in the topology, in this case for ASN1 they are those highlighted in green (local 11.11 .11.22 and remote 11.11.11.20)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPNT1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23221i79B2452D2FC30BBA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPNT1.png" alt="VPNT1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We repeat the same step for the VPN against ASN2, we will change the peering IPs, as shown in the topology the IPs to use would be the purple ones (local 20.20.20.22 and remote 20.20.20.23), we choose the ID = 2 for this VPN.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPNT2.png" style="width: 365px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23222i71A789C04A725C24/image-dimensions/365x270?v=v2" width="365" height="270" role="button" title="VPNT2.png" alt="VPNT2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Once the VPN-tunnel interfaces have been created, it would look like this.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN_interf.png" style="width: 559px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23223i0CFD11E4D0F6A7E4/image-dimensions/559x102?v=v2" width="559" height="102" role="button" title="VPN_interf.png" alt="VPN_interf.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In the Advanced Routing &amp;gt; BGP &amp;gt; Change Global Settings option, configure your Router ID (in my case I assigned the IP of my external interface 3.3.3.254) and your AS number, which in my case I set 65000.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ID_AS.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23225i20BB1EFD71723365/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ID_AS.png" alt="ID_AS.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In the same section of Advanced Routing &amp;gt; BGP, we will add the BGP peers for both VPNS.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Peer_BGP.png" style="width: 505px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23227i4090302748400BED/image-dimensions/505x111?v=v2" width="505" height="111" role="button" title="Peer_BGP.png" alt="Peer_BGP.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In the BGP Peer, we must place the remote AS as well as the remote peer with which we create the VPN-tunnel interfaces. Don't forget that we must enable the eBGP Multihop option.&amp;nbsp;We repeat the same for the ASN2 peer&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Peer_BGP_AS65100.png" style="width: 430px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23228i9C402A64E300C60D/image-dimensions/430x188?v=v2" width="430" height="188" role="button" title="Peer_BGP_AS65100.png" alt="Peer_BGP_AS65100.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Peer_BGP_AS65100_1.png" style="width: 429px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23229i07656BC67391CBD5/image-dimensions/429x177?v=v2" width="429" height="177" role="button" title="Peer_BGP_AS65100_1.png" alt="Peer_BGP_AS65100_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We will allow all the networks that the remote peer with AS 65100 and 65200 publish to us in the "inbound route filters" option. I am setting the VPN with ASN1 (AS 65100) to be the primary one using the weights (green underline)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="inbound.png" style="width: 566px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23230i9A5743E41836B7CC/image-dimensions/566x205?v=v2" width="566" height="205" role="button" title="inbound.png" alt="inbound.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In the "Route Redistribution" section I am publishing my network from eth1 to peers AS65100 and AS65200.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="distribuir.png" style="width: 527px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23231iA779383DEE4777A9/image-dimensions/527x166?v=v2" width="527" height="166" role="button" title="distribuir.png" alt="distribuir.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Once configured at the GAIA level, we configure at the SMC level.&lt;/P&gt;&lt;P&gt;We created the 2 domains for both VPNs without anything.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Domain_asn1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23233iCCC58F187012B68C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Domain_asn1.png" alt="Domain_asn1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Domain_asn2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23232i1CF7E18DD02243A9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Domain_asn2.png" alt="Domain_asn2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We create the "Interoperable Device" with the public IP of the other end, and with the respective domain that we just created.&amp;nbsp;We follow the same sequence for ASN2.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Peer_ASN1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23235i4B7F35FD8B69AC07/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Peer_ASN1.png" alt="Peer_ASN1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Peer_ASN1_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23234i4D9A5EF01DB0C05F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Peer_ASN1_1.png" alt="Peer_ASN1_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We create a star community with the following steps, repeat the same process for ASN2&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1_1.png" style="width: 469px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23242i9118C78C189FFF6A/image-dimensions/469x318?v=v2" width="469" height="318" role="button" title="VPN1_1.png" alt="VPN1_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1_2.png" style="width: 445px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23243i7F60B9C3109376CF/image-dimensions/445x376?v=v2" width="445" height="376" role="button" title="VPN1_2.png" alt="VPN1_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1_3.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23244iC73AA524C0861DEE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN1_3.png" alt="VPN1_3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1_4.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23246i977E8FFB54D041F2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN1_4.png" alt="VPN1_4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In this case, I am not using nateo, but if you want to use it, do not enable that option.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1_5.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23245i1B4F2369EBD33699/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN1_5.png" alt="VPN1_5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;RULE.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RULE.png" style="width: 763px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23247iE16959FFBF2811D0/image-dimensions/763x61?v=v2" width="763" height="61" role="button" title="RULE.png" alt="RULE.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;After the configurations on the checkpoint side and the configurations of the remote devices, the BGP neighborhood is established with both peers (ASN1 and ASN2), in this case I have configured that both ASN2 and ASN2 publish the HOST network. REMOTE towards the checkpoint.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="establecido_ASN1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23248i2619AB603B4F049D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="establecido_ASN1.png" alt="establecido_ASN1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="establecido_ASN2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23249iAB0B21CB55D65DC2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="establecido_ASN2.png" alt="establecido_ASN2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Networks received and published using BGP.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Publicación de redes.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23250iEA68BEFFDBC471BB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Publicación de redes.png" alt="Publicación de redes.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Redes_received.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23251i3F5AEEC00ADB8464/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Redes_received.png" alt="Redes_received.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Routes at the checkpoint.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="show_route.png" style="width: 493px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23252i57247C877CECD465/image-dimensions/493x222?v=v2" width="493" height="222" role="button" title="show_route.png" alt="show_route.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;VPNs UP.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UP_ASN1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23253i6874A846F9A8ABA7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="UP_ASN1.png" alt="UP_ASN1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UP_ASN2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23254i74020C0E7FEC2F4A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="UP_ASN2.png" alt="UP_ASN2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Connectivity test through VPN_ASN1&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Test_ping_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23255i5C1F68F056D40A55/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Test_ping_1.png" alt="Test_ping_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Test_ping.png" style="width: 546px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23256i74B158BD89DEC8C6/image-dimensions/546x258?v=v2" width="546" height="258" role="button" title="Test_ping.png" alt="Test_ping.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Failover test&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;In the simulated environment, I observed that during the failover 3 ping packets were lost, after which the connection was kept constant by the backup VPN that is with ASN2, the test was performed in reverse and 2 ICMP packets were obtained, and then The connection remained constant. As far as I can tell the setup is functional.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="failover_test_1.png" style="width: 587px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23259iC0E7FFF52DFB0F78/image-dimensions/587x239?v=v2" width="587" height="239" role="button" title="failover_test_1.png" alt="failover_test_1.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="failover_test_2.png" style="width: 554px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23258i94E523ADDB8C496B/image-dimensions/554x245?v=v2" width="554" height="245" role="button" title="failover_test_2.png" alt="failover_test_2.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="failover_test_3.png" style="width: 445px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23260iD02AABA1651F1A25/image-dimensions/445x307?v=v2" width="445" height="307" role="button" title="failover_test_3.png" alt="failover_test_3.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 15 Nov 2023 19:27:57 GMT</pubDate>
    <dc:creator>Kebin23</dc:creator>
    <dc:date>2023-11-15T19:27:57Z</dc:date>
    <item>
      <title>Redundant VPN over BGP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Redundant-VPN-over-BGP/m-p/198087#M33166</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;&lt;P&gt;I have carried out a laboratory to test redundant VPNs over BGP, I share with you the topology of my environment and the configurations on the checkpoint side, I hope it helps you.&lt;/P&gt;&lt;P&gt;LAB.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LAB_TOPLGY.png" style="width: 520px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23224i1EB70BD687FDE47C/image-dimensions/520x356?v=v2" width="520" height="356" role="button" title="LAB_TOPLGY.png" alt="LAB_TOPLGY.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;ASN1 and ASN2 are the remote gateways with which I will set up the VPNs.&lt;/P&gt;&lt;P&gt;&lt;U&gt;OBJECTIVE:&lt;/U&gt; The "HOST_LOCAL" connects with the "HOST_REMOTE" through a VPN over BGP with ASN1, if this VPN goes down, there will be a VPN over BGP with ASN2 to reach the "HOST_REMOTE" again, guaranteeing that connectivity is not lost between both hosts using VPNs.&lt;/P&gt;&lt;P&gt;&lt;U&gt;Configuration at the checkpoint.&lt;/U&gt;&lt;/P&gt;&lt;P&gt;At the GAIA level, we create a VPN-tunnel interface, where we define the tunnel ID, in this case 1, and we will place the peering IPs that we have defined in the topology, in this case for ASN1 they are those highlighted in green (local 11.11 .11.22 and remote 11.11.11.20)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPNT1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23221i79B2452D2FC30BBA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPNT1.png" alt="VPNT1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We repeat the same step for the VPN against ASN2, we will change the peering IPs, as shown in the topology the IPs to use would be the purple ones (local 20.20.20.22 and remote 20.20.20.23), we choose the ID = 2 for this VPN.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPNT2.png" style="width: 365px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23222i71A789C04A725C24/image-dimensions/365x270?v=v2" width="365" height="270" role="button" title="VPNT2.png" alt="VPNT2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Once the VPN-tunnel interfaces have been created, it would look like this.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN_interf.png" style="width: 559px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23223i0CFD11E4D0F6A7E4/image-dimensions/559x102?v=v2" width="559" height="102" role="button" title="VPN_interf.png" alt="VPN_interf.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In the Advanced Routing &amp;gt; BGP &amp;gt; Change Global Settings option, configure your Router ID (in my case I assigned the IP of my external interface 3.3.3.254) and your AS number, which in my case I set 65000.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ID_AS.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23225i20BB1EFD71723365/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ID_AS.png" alt="ID_AS.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In the same section of Advanced Routing &amp;gt; BGP, we will add the BGP peers for both VPNS.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Peer_BGP.png" style="width: 505px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23227i4090302748400BED/image-dimensions/505x111?v=v2" width="505" height="111" role="button" title="Peer_BGP.png" alt="Peer_BGP.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In the BGP Peer, we must place the remote AS as well as the remote peer with which we create the VPN-tunnel interfaces. Don't forget that we must enable the eBGP Multihop option.&amp;nbsp;We repeat the same for the ASN2 peer&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Peer_BGP_AS65100.png" style="width: 430px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23228i9C402A64E300C60D/image-dimensions/430x188?v=v2" width="430" height="188" role="button" title="Peer_BGP_AS65100.png" alt="Peer_BGP_AS65100.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Peer_BGP_AS65100_1.png" style="width: 429px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23229i07656BC67391CBD5/image-dimensions/429x177?v=v2" width="429" height="177" role="button" title="Peer_BGP_AS65100_1.png" alt="Peer_BGP_AS65100_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We will allow all the networks that the remote peer with AS 65100 and 65200 publish to us in the "inbound route filters" option. I am setting the VPN with ASN1 (AS 65100) to be the primary one using the weights (green underline)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="inbound.png" style="width: 566px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23230i9A5743E41836B7CC/image-dimensions/566x205?v=v2" width="566" height="205" role="button" title="inbound.png" alt="inbound.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In the "Route Redistribution" section I am publishing my network from eth1 to peers AS65100 and AS65200.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="distribuir.png" style="width: 527px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23231iA779383DEE4777A9/image-dimensions/527x166?v=v2" width="527" height="166" role="button" title="distribuir.png" alt="distribuir.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Once configured at the GAIA level, we configure at the SMC level.&lt;/P&gt;&lt;P&gt;We created the 2 domains for both VPNs without anything.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Domain_asn1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23233iCCC58F187012B68C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Domain_asn1.png" alt="Domain_asn1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Domain_asn2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23232i1CF7E18DD02243A9/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Domain_asn2.png" alt="Domain_asn2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We create the "Interoperable Device" with the public IP of the other end, and with the respective domain that we just created.&amp;nbsp;We follow the same sequence for ASN2.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Peer_ASN1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23235i4B7F35FD8B69AC07/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Peer_ASN1.png" alt="Peer_ASN1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Peer_ASN1_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23234i4D9A5EF01DB0C05F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Peer_ASN1_1.png" alt="Peer_ASN1_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;We create a star community with the following steps, repeat the same process for ASN2&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1_1.png" style="width: 469px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23242i9118C78C189FFF6A/image-dimensions/469x318?v=v2" width="469" height="318" role="button" title="VPN1_1.png" alt="VPN1_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1_2.png" style="width: 445px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23243i7F60B9C3109376CF/image-dimensions/445x376?v=v2" width="445" height="376" role="button" title="VPN1_2.png" alt="VPN1_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1_3.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23244iC73AA524C0861DEE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN1_3.png" alt="VPN1_3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1_4.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23246i977E8FFB54D041F2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN1_4.png" alt="VPN1_4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In this case, I am not using nateo, but if you want to use it, do not enable that option.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN1_5.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23245i1B4F2369EBD33699/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN1_5.png" alt="VPN1_5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;RULE.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RULE.png" style="width: 763px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23247iE16959FFBF2811D0/image-dimensions/763x61?v=v2" width="763" height="61" role="button" title="RULE.png" alt="RULE.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;After the configurations on the checkpoint side and the configurations of the remote devices, the BGP neighborhood is established with both peers (ASN1 and ASN2), in this case I have configured that both ASN2 and ASN2 publish the HOST network. REMOTE towards the checkpoint.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="establecido_ASN1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23248i2619AB603B4F049D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="establecido_ASN1.png" alt="establecido_ASN1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="establecido_ASN2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23249iAB0B21CB55D65DC2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="establecido_ASN2.png" alt="establecido_ASN2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Networks received and published using BGP.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Publicación de redes.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23250iEA68BEFFDBC471BB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Publicación de redes.png" alt="Publicación de redes.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Redes_received.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23251i3F5AEEC00ADB8464/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Redes_received.png" alt="Redes_received.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Routes at the checkpoint.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="show_route.png" style="width: 493px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23252i57247C877CECD465/image-dimensions/493x222?v=v2" width="493" height="222" role="button" title="show_route.png" alt="show_route.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;VPNs UP.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UP_ASN1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23253i6874A846F9A8ABA7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="UP_ASN1.png" alt="UP_ASN1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="UP_ASN2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23254i74020C0E7FEC2F4A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="UP_ASN2.png" alt="UP_ASN2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Connectivity test through VPN_ASN1&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Test_ping_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23255i5C1F68F056D40A55/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Test_ping_1.png" alt="Test_ping_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Test_ping.png" style="width: 546px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23256i74B158BD89DEC8C6/image-dimensions/546x258?v=v2" width="546" height="258" role="button" title="Test_ping.png" alt="Test_ping.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Failover test&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;In the simulated environment, I observed that during the failover 3 ping packets were lost, after which the connection was kept constant by the backup VPN that is with ASN2, the test was performed in reverse and 2 ICMP packets were obtained, and then The connection remained constant. As far as I can tell the setup is functional.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="failover_test_1.png" style="width: 587px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23259iC0E7FFF52DFB0F78/image-dimensions/587x239?v=v2" width="587" height="239" role="button" title="failover_test_1.png" alt="failover_test_1.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="failover_test_2.png" style="width: 554px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23258i94E523ADDB8C496B/image-dimensions/554x245?v=v2" width="554" height="245" role="button" title="failover_test_2.png" alt="failover_test_2.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="failover_test_3.png" style="width: 445px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23260iD02AABA1651F1A25/image-dimensions/445x307?v=v2" width="445" height="307" role="button" title="failover_test_3.png" alt="failover_test_3.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 19:27:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Redundant-VPN-over-BGP/m-p/198087#M33166</guid>
      <dc:creator>Kebin23</dc:creator>
      <dc:date>2023-11-15T19:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Redundant VPN over BGP</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Redundant-VPN-over-BGP/m-p/198090#M33167</link>
      <description>&lt;P&gt;In the part of "Routes at the checkpoint." from the post, I got confused about the screenshot, the correct one is the one I attached, since the main route at the beginning is "vpnt1"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="show_route.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23261i93293E27CE00B5AE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="show_route.png" alt="show_route.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 19:33:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Redundant-VPN-over-BGP/m-p/198090#M33167</guid>
      <dc:creator>Kebin23</dc:creator>
      <dc:date>2023-11-15T19:33:21Z</dc:date>
    </item>
  </channel>
</rss>

