<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Harmony sase vpn redundant vpn tunnel tip in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252941#M1171</link>
    <description>&lt;P&gt;Ah, I see what you are saying. Thats true, we can always do that, but we would definitely prefer that process be documented somewhere officially, so there is no ambiguity.&lt;/P&gt;
&lt;P&gt;Anywho, lets see what SE says : - )&lt;/P&gt;
&lt;P&gt;Thanks Val as always!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jul 2025 12:23:45 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-07-10T12:23:45Z</dc:date>
    <item>
      <title>Harmony sase vpn redundant vpn tunnel tip</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252716#M1165</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;Figured would share this, since my colleague and I spent lots of hours into testing this with BGP for a client that purchased SASE solution. Since sd-wan is not supported yet and we dont have an idea when it will be with sase, we made it work where redundant vpn tunnels work flawlessly with BGP implemented.&lt;/P&gt;
&lt;P&gt;Guide:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/SASE-Admin-Guide/Content/Topics-SASE-IPsec-VPN/On-premises/ConfiguringCheckPointRedundantIPSecTunnel.htm?tocpath=Networks%7CIntegrating%20On-premises%20Firewall%20%252F%20Router%20or%20Cloud%20based%20Resources%7COn-premises%20Firewall%20-%20Configuring%20the%20Tunnel%20in%20the%20Management%20Portal%7C_____5" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/SASE-Admin-Guide/Content/Topics-SASE-IPsec-VPN/On-premises/ConfiguringCheckPointRedundantIPSecTunnel.htm?tocpath=Networks%7CIntegrating%20On-premises%20Firewall%20%252F%20Router%20or%20Cloud%20based%20Resources%7COn-premises%20Firewall%20-%20Configuring%20the%20Tunnel%20in%20the%20Management%20Portal%7C_____5&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;But, the way to make this work 100% is NOT to set it where you have CP cluster as center gw and interoperable objects presenting sase pops as satellite, but the other way around, where interoperable ones are center and CP is satellite and then you enable MEP and choose middle option (default one, closest choise) in vpn community (should be configured as star)&lt;/P&gt;
&lt;P&gt;This works without issues. We will actually show this to CP sase expert, as well as SE guy when we have a call with them, so documentation can be hopefully modified to reflect that, as it would save lots of time for others trying to do the same.&lt;/P&gt;
&lt;P&gt;We are using BGP per overlay, since we found works better that way, mind you, using BGP loopback interface does offer better scalability.&lt;/P&gt;
&lt;P&gt;Happy to share any screenshots if needed.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jul 2025 23:30:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252716#M1165</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-07T23:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony sase vpn redundant vpn tunnel tip</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252911#M1166</link>
      <description>&lt;P&gt;Do share the screenshots &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 08:15:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252911#M1166</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-10T08:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony sase vpn redundant vpn tunnel tip</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252931#M1167</link>
      <description>&lt;P&gt;Since we want to make sure this would be officially supported by CP, we asked our SE if sk could be written about it, or at least included in the documentation. Obviously, we dont want client to have an issue say a year from today and then we are told by TAC this is not supported...anyway, lets see what comes out of that, but regardless, screenshots attached : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 11:49:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252931#M1167</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-10T11:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony sase vpn redundant vpn tunnel tip</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252937#M1168</link>
      <description>&lt;P&gt;Or you can ask TAC about the support status. It is considered an official answer.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 11:59:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252937#M1168</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-10T11:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony sase vpn redundant vpn tunnel tip</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252938#M1169</link>
      <description>&lt;P&gt;Speaking of that, we figured it would be best to go through our SE, but if you have an email or contact I could present this to, that would work as well.&lt;/P&gt;
&lt;P&gt;Thanks Val.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 12:01:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252938#M1169</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-10T12:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony sase vpn redundant vpn tunnel tip</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252940#M1170</link>
      <description>&lt;P&gt;What I mean, you can open a TAC ticket to ask about the support status.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 12:21:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252940#M1170</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-10T12:21:10Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony sase vpn redundant vpn tunnel tip</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252941#M1171</link>
      <description>&lt;P&gt;Ah, I see what you are saying. Thats true, we can always do that, but we would definitely prefer that process be documented somewhere officially, so there is no ambiguity.&lt;/P&gt;
&lt;P&gt;Anywho, lets see what SE says : - )&lt;/P&gt;
&lt;P&gt;Thanks Val as always!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jul 2025 12:23:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Harmony-sase-vpn-redundant-vpn-tunnel-tip/m-p/252941#M1171</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-10T12:23:45Z</dc:date>
    </item>
  </channel>
</rss>

