<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Site2Site, 2 Tunnels in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253934#M42651</link>
    <description>&lt;P&gt;Hello Andy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;domain overlap is on the peer side ( Cisco ASA), i can't configure MEP on my side,&amp;nbsp; i dont know if traffic failsover automaticly with this config ( schema attached)&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Jul 2025 08:55:09 GMT</pubDate>
    <dc:creator>Ayoub_Bou</dc:creator>
    <dc:date>2025-07-25T08:55:09Z</dc:date>
    <item>
      <title>VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253580#M42575</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to setup 2 Tunnels&amp;nbsp; toward a partner( from Checkpoint R81.20 to Cisco ASA); how can i achieve&amp;nbsp; failover from first tunnel to second in case of failure? (Attached the schema).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 13:22:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253580#M42575</guid>
      <dc:creator>Ayoub_Bou</dc:creator>
      <dc:date>2025-07-21T13:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253618#M42584</link>
      <description>&lt;P&gt;To me, based on what you attached, seems like it would make sense to set one meshed community and have all 3 gateways included (2 Cisco sites would be presented as interoperable objects). That way, if say one Cisco side goes down, tunnel would still work to the other one.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 18:36:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253618#M42584</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-21T18:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253664#M42597</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your reply, is there any SK on how to configure this?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 09:48:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253664#M42597</guid>
      <dc:creator>Ayoub_Bou</dc:creator>
      <dc:date>2025-07-22T09:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253666#M42599</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Consider using tunnel interfaces (VTI's) and a routing protocol (OSPF).&lt;BR /&gt;&lt;BR /&gt;If a VTI goes down, OSPF will use the other VTI to route traffic.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Martijn&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 10:26:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253666#M42599</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2025-07-22T10:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253670#M42600</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/CP_R82_SitetoSiteVPN_AdminGuide.pdf" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_SitetoSiteVPN_AdminGuide/CP_R82_SitetoSiteVPN_AdminGuide.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 11:15:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253670#M42600</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-22T11:15:42Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253684#M42604</link>
      <description>&lt;P&gt;it's impossible to have the same encryption domain to 2 different&amp;nbsp;&lt;SPAN&gt;interoperable objects&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 14:34:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253684#M42604</guid>
      <dc:creator>Ayoub_Bou</dc:creator>
      <dc:date>2025-07-22T14:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253685#M42605</link>
      <description>&lt;P&gt;Sure you can.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 14:36:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253685#M42605</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-22T14:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253686#M42606</link>
      <description>&lt;P&gt;Btw, I would do what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3058"&gt;@Martijn&lt;/a&gt;&amp;nbsp;suggested, makes total sense. Also, you can set enc domains as empty group for everything (Cisco and CP), but make sure traffic is controlled with the correct rule, ie include whatever subnets need to participate.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 14:44:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253686#M42606</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-22T14:44:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253736#M42617</link>
      <description>&lt;P&gt;Hi, thank you for your reply, i only manage the checkpoint cluster, ospf neeed to be configured on cisco ASA(managed by partner) as well?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 07:55:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253736#M42617</guid>
      <dc:creator>Ayoub_Bou</dc:creator>
      <dc:date>2025-07-23T07:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253737#M42618</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Yes, OSPF needs to be configured on both end of the VPN tunnel.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 08:00:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253737#M42618</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2025-07-23T08:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253800#M42632</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;routing with VTI is difficult to implement, our partner is not too technical, i found in a threat that it's possible, 1 community ,2 i&lt;SPAN&gt;nteroperable GW, same encryption domain,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/2-VPN-s-Same-Remote-Encryption-Domain/td-p/208000" target="_blank"&gt;2 VPN's Same Remote Encryption Domain - Check Point CheckMates&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 14:55:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253800#M42632</guid>
      <dc:creator>Ayoub_Bou</dc:creator>
      <dc:date>2025-07-23T14:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253803#M42633</link>
      <description>&lt;P&gt;Its actually pretty simply. But, I mean, like anything in life, things are easy when you know it : - ). Anyway, check out link I posted while back about doing this for Azure vpn tunnel, hope it helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Route-based-VPN-tunnel-to-Azure/m-p/206179/emcs_t/S2h8ZW1haWx8dG9waWNfc3Vic2NyaXB0aW9ufExTTjlYV1FXMUlGQVNMfDIwNjE3OXxTVUJTQ1JJUFRJT05TfGhL#M38950&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 15:02:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253803#M42633</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-23T15:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253842#M42635</link>
      <description>&lt;P&gt;The solution is to use explicit MEP (&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/MEP.htm" target="_blank" rel="noopener"&gt;Multiple Entry Point&lt;/A&gt;) feature inside VPN Community settings.&lt;/P&gt;
&lt;P&gt;Site1 and Site2 will use the same VPN encryption domain. Inside MEP settings, Site1 can be set as Primary gateway and in case Site1 is not responding, VPN will switch to use Site2.&lt;/P&gt;
&lt;P&gt;There is also option to use &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/MEP.htm?tocpath=Multiple%20Entry%20Point%20(MEP)%20VPNs%7C_____3#Implicit_MEP" target="_blank" rel="noopener"&gt;implicit MEP&lt;/A&gt; where you can choose which gateway should be used as primary and which as backup.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 06:24:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253842#M42635</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2025-07-24T06:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253868#M42636</link>
      <description>&lt;P&gt;You got it!&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/26123"&gt;@Ayoub_Bou&lt;/a&gt;&amp;nbsp;, implicit MEP option would be used if vpn domains overlap.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2025 10:48:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253868#M42636</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-24T10:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253933#M42650</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;in my environement, there is one single entry( Checkpoint Cluster), and the satellilte gateways are not managed by me&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 08:51:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253933#M42650</guid>
      <dc:creator>Ayoub_Bou</dc:creator>
      <dc:date>2025-07-25T08:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253934#M42651</link>
      <description>&lt;P&gt;Hello Andy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;domain overlap is on the peer side ( Cisco ASA), i can't configure MEP on my side,&amp;nbsp; i dont know if traffic failsover automaticly with this config ( schema attached)&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jul 2025 08:55:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253934#M42651</guid>
      <dc:creator>Ayoub_Bou</dc:creator>
      <dc:date>2025-07-25T08:55:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Site2Site, 2 Tunnels</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253990#M42661</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Just swap Center gateways with Satellite Gateways each other.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jul 2025 06:43:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Site2Site-2-Tunnels/m-p/253990#M42661</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2025-07-26T06:43:08Z</dc:date>
    </item>
  </channel>
</rss>

