<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPsec VPN between Checkpoint and Remote Server in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259229#M43828</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;, Can you please share any related SK or document?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Saranya&lt;/P&gt;</description>
    <pubDate>Tue, 07 Oct 2025 11:07:56 GMT</pubDate>
    <dc:creator>Saranya_0305</dc:creator>
    <dc:date>2025-10-07T11:07:56Z</dc:date>
    <item>
      <title>IPsec VPN between Checkpoint and Remote Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259082#M43788</link>
      <description>&lt;P&gt;Dear Mates,&lt;/P&gt;&lt;P&gt;I am having Cluster setup running in R81.10 and Management Server in R81.20.&lt;/P&gt;&lt;P&gt;My firewalls having two ISPs(external interfaces) which are in ISP redundancy mode.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I want to create a IPsec VPN tunnel between Firewall and third party Remote server directly,&amp;nbsp; it it possible?&lt;/P&gt;&lt;P&gt;If it is possible then how can I use my two ISPs?&lt;/P&gt;&lt;P&gt;- Do I need to make two different IPsec tunnels? If yes, will they&amp;nbsp; work redundancy mode automatically or we need to manually?&lt;/P&gt;&lt;P&gt;- Can we do FQDN and map those two ISPs to that FQDN and create IPsec tunnel?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone please suggest me?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Saranya&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2025 07:47:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259082#M43788</guid>
      <dc:creator>Saranya_0305</dc:creator>
      <dc:date>2025-10-06T07:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN between Checkpoint and Remote Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259094#M43793</link>
      <description>&lt;P&gt;I believe it would have to be manual option, unless you have routes with different priorities, so if main one fails, then other one will take over. Here is my reasoning for it...if you think about it logically, say you have VPN with Cisco or Fortinet or PAN, whatever really. IF main link fails, well, there is no way other side would "know" about new ISP link, so tunnel would never re-establish.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 06 Oct 2025 11:28:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259094#M43793</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-06T11:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN between Checkpoint and Remote Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259200#M43826</link>
      <description>&lt;P&gt;Can we map two different vendor ISPs IP to single FQDN and make VPN tunnel?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Saranya&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 09:35:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259200#M43826</guid>
      <dc:creator>Saranya_0305</dc:creator>
      <dc:date>2025-10-07T09:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN between Checkpoint and Remote Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259224#M43827</link>
      <description>&lt;P&gt;Im fairly sure you can, you just need 2 A records pointing to same fqdn. I know we did this for a customer while back for remote access.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 10:59:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259224#M43827</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-07T10:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN between Checkpoint and Remote Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259229#M43828</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;, Can you please share any related SK or document?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Saranya&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 11:07:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259229#M43828</guid>
      <dc:creator>Saranya_0305</dc:creator>
      <dc:date>2025-10-07T11:07:56Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN between Checkpoint and Remote Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259230#M43829</link>
      <description>&lt;P&gt;I know there were 2, one I can easily find, but will check the 2nd one later and update you.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 11:10:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259230#M43829</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-07T11:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN between Checkpoint and Remote Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259262#M43830</link>
      <description>&lt;P&gt;There you go.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk103440" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk103440&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk131612" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk131612&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 12:39:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259262#M43830</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-07T12:39:04Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN between Checkpoint and Remote Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259275#M43831</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;gave info on how you can do this with the Endpoint VPN client, but for site-to-site VPNs with 3rd party gateways, this can't be done with pre-shared keys. &amp;nbsp;If the remote end is willing to do either:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Use a certificate issued by your management internal_ca, or&lt;/LI&gt;
&lt;LI&gt;Use VTI with IKEv2 and universal tunnels &amp;nbsp;(likely the better choice)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With certificate, the remote end can allow your side to appear as a "dynamic IP" VPN peer and allow authentication to rely on the certificate. However, now that we have VTIs and universal tunnels, certificates will be less preferred and instead you should use the VTIs.&lt;/P&gt;
&lt;P&gt;The remote end will build 2 VPN gateways for each of your ISP-provided IPs (or the cluster VIP for each, if you have ISP Redundancy on a cluster). &amp;nbsp;The encryption domains for both you and them will be empty group objects (or, however the remote device does this). &amp;nbsp;You'll then create a VTI on your firewall gateway in CLISH, as will the remote peer. &amp;nbsp;The IPs on the VTIs are irrelevant; VTIs are just point-to-point links and any packet you send to that VTI device will be encrypted and sent to the specified remote peer (specified in the VTI configuration).&lt;/P&gt;
&lt;P&gt;You can use static routing with either primary/secondary priority, or just let it be equal-cost; doesn't matter either way. &amp;nbsp;This is how you do an AWS VPNgw redundant VPN, too.&lt;/P&gt;
&lt;P&gt;The remote peer does the same thing, only in reverse, with a VTI on their side. &amp;nbsp;They will add static route for your VPN networks across the VTI. &amp;nbsp;Configure the VPN community tunnel management as "one tunnel per gateway pair" and you're done.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 13:30:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259275#M43831</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-10-07T13:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: IPsec VPN between Checkpoint and Remote Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259276#M43832</link>
      <description>&lt;P&gt;I got this document from someone in community while ago, not sure it may help in this case, but here it is anyway &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 13:36:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IPsec-VPN-between-Checkpoint-and-Remote-Server/m-p/259276#M43832</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-07T13:36:05Z</dc:date>
    </item>
  </channel>
</rss>

