<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to deliver Redundancy for VPN Site2Site on VSX within Maestro? in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/145359#M874</link>
    <description>&lt;P&gt;Customer were running out of budget but was eager to buy Maestro for it's hyperscaling capability, so they wanted firewalls to be deployed as VS, and we forgot if they need ISP Redundancy or VTI/Route-based VPN to give VPN Site2Site redundancy (which is not supported in VSX). CP 2200 is the 3rd Party connected to the customer, it was deployed with VTI tunneling.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Apr 2022 10:58:39 GMT</pubDate>
    <dc:creator>sonofgod031</dc:creator>
    <dc:date>2022-04-04T10:58:39Z</dc:date>
    <item>
      <title>How to deliver Redundancy for VPN Site2Site on VSX within Maestro?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/144948#M854</link>
      <description>&lt;P&gt;Is it possible to deliver VPN Site2Site with redundancy in VSX deployment using Maestro?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Old Firewall (CP 4800) used to connect Site2Site VPN to 3rd Party (CP 2200) with ISP Redundancy (2&amp;nbsp; ISP's), so that VPN Site2Site have redundancy (automatically failover if 1 ISP is down).&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;CP 4800 will be replaced with Maestro with VSX deployment, sk79700 says VSX doesn’t support ISP Redundancy.&lt;BR /&gt;I saw a thread that says the alternative way to give Redundancy in VPN Site2Site is using PBR Multi Hop and it’s available from R80.30 onwards.&lt;BR /&gt;Since Maestro OS is R80.20 SP, I haven’t found SK that declares R80.20SP Supports PBR Multihop, I only found that PBR can be setup in VSX Maestro sk137232.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or is there another alternative solution to give Redundancy on VPN Site2Site using VSX?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sk79700 (VSX doesn't support ISP Redundancy):&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk79700" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk79700&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Alternative Solution:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/General-Topics/PBR-With-Multiple-Tracking/td-p/14462" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/PBR-With-Multiple-Tracking/td-p/14462&lt;/A&gt;&lt;/P&gt;&lt;P&gt;sk137232 (How to setup PBR in VSX on High Scalable Device)&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk137232" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk137232&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#VSX #Maestro #VPN&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 02:35:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/144948#M854</guid>
      <dc:creator>sonofgod031</dc:creator>
      <dc:date>2022-03-29T02:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to deliver Redundancy for VPN Site2Site on VSX within Maestro?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/144949#M855</link>
      <description>&lt;P&gt;Could you please specify what exactly you need, IPS redundancy, S2S VPN redundancy, or both?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 06:54:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/144949#M855</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-03-29T06:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to deliver Redundancy for VPN Site2Site on VSX within Maestro?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/144952#M856</link>
      <description>&lt;P&gt;Given the sunset approaches for R80.20SP please consider adopting R81.10 that has route-based VPN support for VSX.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 07:26:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/144952#M856</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-03-29T07:26:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to deliver Redundancy for VPN Site2Site on VSX within Maestro?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/145004#M857</link>
      <description>&lt;P&gt;I need VPN Site2Site to have automatic failover function (on Maestro with VSX deploymnet), so if the tunnel that goes through ISP1 is down, VPN will automatically failover to ISP2, so downtime can be minimized.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 18:26:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/145004#M857</guid>
      <dc:creator>sonofgod031</dc:creator>
      <dc:date>2022-03-29T18:26:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to deliver Redundancy for VPN Site2Site on VSX within Maestro?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/145005#M858</link>
      <description>&lt;P&gt;When is R81.10 will be available for Maestro?&lt;/P&gt;&lt;P&gt;Customer is already using R80.20SP and the Maestro has been implemented in their environment&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_sweat:"&gt;😅&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If this is the only solution, then i can tell them to wait until R81.10 for Maestro to be released.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 18:30:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/145005#M858</guid>
      <dc:creator>sonofgod031</dc:creator>
      <dc:date>2022-03-29T18:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to deliver Redundancy for VPN Site2Site on VSX within Maestro?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/145010#M859</link>
      <description>&lt;P&gt;According to this diagram, you do need your GW to support ISP redundancy. Now, why Maestro + VSX, if you are coming from 2200 appliance?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 19:42:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/145010#M859</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-03-29T19:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to deliver Redundancy for VPN Site2Site on VSX within Maestro?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/145040#M860</link>
      <description>&lt;P&gt;It already is available, refer&amp;nbsp;&lt;SPAN&gt;sk173363&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 10:50:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/145040#M860</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-03-30T10:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to deliver Redundancy for VPN Site2Site on VSX within Maestro?</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/145359#M874</link>
      <description>&lt;P&gt;Customer were running out of budget but was eager to buy Maestro for it's hyperscaling capability, so they wanted firewalls to be deployed as VS, and we forgot if they need ISP Redundancy or VTI/Route-based VPN to give VPN Site2Site redundancy (which is not supported in VSX). CP 2200 is the 3rd Party connected to the customer, it was deployed with VTI tunneling.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 10:58:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/How-to-deliver-Redundancy-for-VPN-Site2Site-on-VSX-within/m-p/145359#M874</guid>
      <dc:creator>sonofgod031</dc:creator>
      <dc:date>2022-04-04T10:58:39Z</dc:date>
    </item>
  </channel>
</rss>

