<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPSec Amazon without VTI in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-Amazon-without-VTI/m-p/12878#M12901</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's generally less reliable to not use VTIs with Amazon.&lt;/P&gt;&lt;P&gt;See:&amp;nbsp;&lt;A href="https://community.checkpoint.com/message/14458-re-ipsec-tunnel-to-aws-vpc-sporadically-drops-after-policy-install" target="_blank"&gt;https://community.checkpoint.com/message/14458-re-ipsec-tunnel-to-aws-vpc-sporadically-drops-after-policy-install&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You really should consider upgrading to R80.x.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Jun 2019 09:03:10 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-06-21T09:03:10Z</dc:date>
    <item>
      <title>IPSec Amazon without VTI</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-Amazon-without-VTI/m-p/12877#M12900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Site2Site VPN (Amazon - Company)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're running a firewall cluster based on R77.30 and what to setup a IPsec VPN tunnel with Amazon VPC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But there's a known issue with R77.30 and VTI's&lt;/P&gt;&lt;P&gt;See:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100726&amp;amp;partition=General&amp;amp;product=IPSec" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk100726&amp;amp;partition=General&amp;amp;product=IPSec"&gt;How to configure IPsec VPN tunnel between Check Point Security Gateway and Amazon Web Services VPC using static routes&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/76213_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;If CoreXL is disabled we see a very High CPU usuage.&lt;/P&gt;&lt;P&gt;That's why we want to setup an IPSec without VTI's, instead of updating to R88.10 first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When downloading the Configuration file from Amazon:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Vendor: Generic&lt;/LI&gt;&lt;LI&gt;Platform: Generic&lt;/LI&gt;&lt;LI&gt;Software: Vendor Agnostic&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Within the config file there's a part about the Inside IP Address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE class="j-table jiveBorder" style="border: 1px solid #c6c6c6;" width="100%"&gt;&lt;THEAD&gt;&lt;TR style="background-color: #efefef;"&gt;&lt;TH&gt;The Customer Gateway inside IP address should be configured on your tunnel&lt;BR /&gt;interface.&lt;/TH&gt;&lt;/TR&gt;&lt;/THEAD&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Outside IP Addresses:&lt;BR /&gt;&amp;nbsp; - Customer Gateway &amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : a.b.c.d.&lt;BR /&gt;&amp;nbsp; - Virtual Private Gateway&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : z.y.x.w&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Inside IP Addresses&lt;BR /&gt;&amp;nbsp; - Customer Gateway&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;: 169.254.22.106/30&lt;BR /&gt;&amp;nbsp; - Virtual Private Gateway&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 169.254.22.105/30&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I configure the inside Customer Gateway and Inside Virtual Private Gateway without using VTI's ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following SK article has been followed (sk113840)&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113840" title="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113840"&gt;How to configure IPsec VPN (non-VTI) tunnel between Check Point Security Gateway and Amazon Web Services VPC using stati…&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://aws.amazon.com/premiumsupport/knowledge-center/vpn-cgw-vpg-traffic/" title="https://aws.amazon.com/premiumsupport/knowledge-center/vpn-cgw-vpg-traffic/"&gt;Ensure VPN Tunnels Pass Traffic Between Customer Gateways and Virtual Private Gateways&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please advice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ray&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2018 13:46:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-Amazon-without-VTI/m-p/12877#M12900</guid>
      <dc:creator>Raymond_Poede</dc:creator>
      <dc:date>2018-12-04T13:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec Amazon without VTI</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-Amazon-without-VTI/m-p/12878#M12901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's generally less reliable to not use VTIs with Amazon.&lt;/P&gt;&lt;P&gt;See:&amp;nbsp;&lt;A href="https://community.checkpoint.com/message/14458-re-ipsec-tunnel-to-aws-vpc-sporadically-drops-after-policy-install" target="_blank"&gt;https://community.checkpoint.com/message/14458-re-ipsec-tunnel-to-aws-vpc-sporadically-drops-after-policy-install&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You really should consider upgrading to R80.x.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:03:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IPSec-Amazon-without-VTI/m-p/12878#M12901</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-21T09:03:10Z</dc:date>
    </item>
  </channel>
</rss>

