<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Backup to MPLS in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-Backup-to-MPLS/m-p/29639#M6045</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The main problem with this issue&amp;nbsp; is that you have to use dynamic routing between router an gateway and also between the VPN gateways, the latter can only be achieved when you use VTI's as you can only run a dynamic protocol over a interface.&lt;/P&gt;&lt;P&gt;Think of this one, use the router to setup the VPN to the other location's MPLS router, using NAT on gateways. In fact you're taking the gateway out of the backup equation. The MPLS router will then be able to use priorities for the VPN and MPLS and also does not care to much about asymmetric routing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 02 Feb 2019 07:44:32 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2019-02-02T07:44:32Z</dc:date>
    <item>
      <title>VPN Backup to MPLS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Backup-to-MPLS/m-p/29637#M6043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to come up with a working solution to have a redundant VPN link to a remote site as a backup to the MPLS link already deployed there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since we break out from the DC and MPLS out the Firewall we terminate our VPNs on, I'm struggling&amp;nbsp;to find a way to have the return traffic from the MPLS go back on the MPLS instead out the VPN which is connected and route static.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Breakout&amp;nbsp;CP has OSPF that redistributes in MPLS BGP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know how to route traffic over the MPLS from the site and within the DC. My worry is with the internet traffic that's coming back to the Site. I'm worried about ending up with asymmetric routing and out of state packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas? VPN_Trust is true, Looked at RBP but that is not dynamic based on if the MPLS is available.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2019 11:21:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Backup-to-MPLS/m-p/29637#M6043</guid>
      <dc:creator>Serban_Biliuti</dc:creator>
      <dc:date>2019-02-01T11:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Backup to MPLS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Backup-to-MPLS/m-p/29638#M6044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Serban,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have a topology or proposed topology you are working with? I.e what does the MPLS look like and what are the capabilities of your switching hardware at the remote site you want to make resilient?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Feb 2019 19:52:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Backup-to-MPLS/m-p/29638#M6044</guid>
      <dc:creator>Mark_Mitchell</dc:creator>
      <dc:date>2019-02-01T19:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Backup to MPLS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Backup-to-MPLS/m-p/29639#M6045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The main problem with this issue&amp;nbsp; is that you have to use dynamic routing between router an gateway and also between the VPN gateways, the latter can only be achieved when you use VTI's as you can only run a dynamic protocol over a interface.&lt;/P&gt;&lt;P&gt;Think of this one, use the router to setup the VPN to the other location's MPLS router, using NAT on gateways. In fact you're taking the gateway out of the backup equation. The MPLS router will then be able to use priorities for the VPN and MPLS and also does not care to much about asymmetric routing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 02 Feb 2019 07:44:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Backup-to-MPLS/m-p/29639#M6045</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-02-02T07:44:32Z</dc:date>
    </item>
  </channel>
</rss>

