<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to Site VPN(Route Based) between two clusters in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225804#M37659</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/114636"&gt;@speedbot33&lt;/a&gt;&amp;nbsp;Ping me any time privately if you need help, I respond to all messages.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 05 Sep 2024 16:22:06 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-09-05T16:22:06Z</dc:date>
    <item>
      <title>Site to Site VPN(Route Based) between two clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225715#M37628</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Currently trying to bring up a route based S2S VPN between my two sites which each has 2 GW&amp;nbsp; in ClusterXL each and if it's possible your help on confirming this design.&lt;/P&gt;&lt;P&gt;This is based on this reference, but it kinda threw me off:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Gaia_AdminGuide/Content/Topics-GAG/VPN-Tunnel-Interfaces.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Gaia_AdminGuide/Content/Topics-GAG/VPN-Tunnel-Interfaces.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I'm planning to use static routes, not dynamic routing. So, what's the next hop supposed to be?&lt;/P&gt;&lt;P&gt;I've attached a HLD for a better view of I think I'm supposed to configure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: I've already configured VPN Community and a VPN Domain with an Empty Group as required.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Sep 2024 22:10:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225715#M37628</guid>
      <dc:creator>speedbot33</dc:creator>
      <dc:date>2024-09-04T22:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN(Route Based) between two clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225717#M37629</link>
      <description>&lt;P&gt;So what exactly is failing? Do you see phase 1 and 2 completing?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 00:27:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225717#M37629</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-05T00:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN(Route Based) between two clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225721#M37631</link>
      <description>&lt;P&gt;Nothing is failing since I haven't completed the config. My question is specifically regarding the VTIs when GWs are clustered. Please see the attached HLD.&amp;nbsp;&lt;/P&gt;&lt;P&gt;ClusterA&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ClusterB&amp;nbsp;&lt;/P&gt;&lt;P&gt;Gw1&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;Gw1&lt;/P&gt;&lt;P&gt;Gw2&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;Gw2&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 01:32:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225721#M37631</guid>
      <dc:creator>speedbot33</dc:creator>
      <dc:date>2024-09-05T01:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN(Route Based) between two clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225722#M37632</link>
      <description>&lt;P&gt;Ok, got it. Check out my post below about how this should be configured, though its with Azuire, its similar.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If still not clear, let me know.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 01:34:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225722#M37632</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-05T01:34:30Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN(Route Based) between two clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225789#M37653</link>
      <description>&lt;P&gt;Tnks! The way I see it based on the data you provided:&lt;/P&gt;&lt;P&gt;-Use STAR community instead of Mesh(what I have configured, I figured since they're two clusters P2P ) - What about the whole Center/Hub - spoke thing in STAR? Will that have any impact?&lt;BR /&gt;-Use unnumbered VTIs&amp;nbsp;&lt;BR /&gt;-Static routes pointing towards external intf.&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 14:48:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225789#M37653</guid>
      <dc:creator>speedbot33</dc:creator>
      <dc:date>2024-09-05T14:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN(Route Based) between two clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225796#M37655</link>
      <description>&lt;P&gt;1) Thats right, star is fine, no it should not have any impact&lt;/P&gt;
&lt;P&gt;2) You can use unnumbered VTIs, though I found thats probably more must if you use BGP, but even if you dont, its fine, just dont "freak out" when you see vti pop up with SAME ip as external, thats totally fine and expected, as it would "piggy off" that interface&lt;/P&gt;
&lt;P&gt;3) Yes, BUT, make sure when you create a route it points to REMOTE subnet and dg is actual VTI&lt;/P&gt;
&lt;P&gt;I mentioned all this in post I made I referenced to.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 15:16:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225796#M37655</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-05T15:16:09Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN(Route Based) between two clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225799#M37657</link>
      <description>&lt;P&gt;Got it! And about which one should be center and satellite? What's the best practice?, no SK mentions that!&lt;/P&gt;&lt;P&gt;Also, tunnel management and VPN routing?&lt;/P&gt;&lt;P&gt;I keep thinking that having two clusters on each site it is somewhat different than with a 'cloud based' peer lol!&lt;/P&gt;&lt;P&gt;Based on your worddoc, you placed AZURE as satellite, but in my case, again two clusters managed by the same SMS.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 15:40:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225799#M37657</guid>
      <dc:creator>speedbot33</dc:creator>
      <dc:date>2024-09-05T15:40:39Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN(Route Based) between two clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225802#M37658</link>
      <description>&lt;P&gt;I guess in your case it should not matter, honestly...either one can be centre. VPN routing? Well, are you doing any?&lt;/P&gt;
&lt;P&gt;Below is description of those options.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center only&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. No VPN routing actually occurs. Only connections between the satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;go through the VPN tunnel. Other connections are routed in the normal way&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center and to other satellites through center&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. Use VPN routing for connection between satellites. Every packet passing from a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to another satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is routed through the central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;. Connection between satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gws variable"&gt;gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;that do not belong to the community are routed in the normal way.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;To center, or through the center to other satellites, to internet and other VPN targets&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;. Use VPN routing for every connection a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;handles. Packets sent by a satellite&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;pass through the VPN tunnel to the central&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gw variable"&gt;gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;before being routed to the destination address.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 05 Sep 2024 16:01:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225802#M37658</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-05T16:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN(Route Based) between two clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225804#M37659</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/114636"&gt;@speedbot33&lt;/a&gt;&amp;nbsp;Ping me any time privately if you need help, I respond to all messages.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 16:22:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225804#M37659</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-05T16:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN(Route Based) between two clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225806#M37660</link>
      <description>&lt;P&gt;Thanks a lot Andy! I will take you up on that! let me give it a go with what I've gathered so far and let you know.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 16:25:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225806#M37660</guid>
      <dc:creator>speedbot33</dc:creator>
      <dc:date>2024-09-05T16:25:34Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN(Route Based) between two clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225807#M37661</link>
      <description>&lt;P&gt;Any time. I had someone else message about it few months back and I told guy what to do and worked right away. He was very grateful, as he told me he's been trying to get it work for 6 months, even had TAC case about it, but nothing happened. But, I get the situation...its never easy to fix anything complicated like that unless you have working lab, otherwise, you just keep guessing and thats no way to really fix things lol&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 16:29:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225807#M37661</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-05T16:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN(Route Based) between two clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225808#M37662</link>
      <description>&lt;P&gt;I've tried several times to boot up an virtual GW in EVENG but to no avail.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Btw - I appreciate giving me the heads up on vti placing the external IP - After I pulled interfaces WITHOUT topology - boom. This my first foray into Unnumbered interfaces with CP.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 16:35:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225808#M37662</guid>
      <dc:creator>speedbot33</dc:creator>
      <dc:date>2024-09-05T16:35:36Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site VPN(Route Based) between two clusters</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225809#M37663</link>
      <description>&lt;P&gt;Try different NIC types, I always choose vmxnet, no issues.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 05 Sep 2024 16:37:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Site-to-Site-VPN-Route-Based-between-two-clusters/m-p/225809#M37663</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-05T16:37:15Z</dc:date>
    </item>
  </channel>
</rss>

