<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 2 Sites with same VPN domain without MEP in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Sites-with-same-VPN-domain-without-MEP/m-p/197810#M4394</link>
    <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have primary VPN site for our VPN clients but we want some of them to use secondary.&lt;/P&gt;&lt;P&gt;Primary site and secondary site is managed by same SMS, they are connected over MPLS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Primary site is cluster with 5600 and secondary is open server, they all run on latest R81.20 with HF26.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried disabling MEP and Secondary Connect but primary site is showing problems. Ill need to remove/add vpn site everytime to work. First time VPN will connect, and second time will immediately drop.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have read this and pretty much i have same issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/Two-Gateways-Serving-the-Same-Encryption-Domain/td-p/178621" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/Two-Gateways-Serving-the-Same-Encryption-Domain/td-p/178621&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"trac_client_1.ttm" file edited on all GWs, example bellow is from Site1 GW.&amp;nbsp;&lt;/P&gt;&lt;P&gt;)&lt;BR /&gt;)&lt;BR /&gt;:mep_mode (&lt;BR /&gt;:gateway (&lt;BR /&gt;:map (&lt;BR /&gt;:dns_based (dns_based)&lt;BR /&gt;:first_to_respond (first_to_respond)&lt;BR /&gt;:primary_backup (primary_backup)&lt;BR /&gt;:load_sharing (load_sharing)&lt;BR /&gt;:client_decide (client_decide)&lt;BR /&gt;)&lt;BR /&gt;:default (primary_backup)&lt;BR /&gt;)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;)&lt;BR /&gt;)&lt;BR /&gt;:ips_of_gws_in_mep (&lt;BR /&gt;:gateway (&lt;BR /&gt;:default (Site1externalIP1&amp;amp;#Site1externalIP2&amp;amp;#)&lt;BR /&gt;)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;)&lt;BR /&gt;)&lt;BR /&gt;:automatic_mep_topology (&lt;BR /&gt;:gateway (&lt;BR /&gt;:map (&lt;BR /&gt;:false (false)&lt;BR /&gt;:true (true)&lt;BR /&gt;:client_decide (false)&lt;BR /&gt;)&lt;BR /&gt;:default (false)&lt;BR /&gt;)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;)&lt;BR /&gt;)&lt;BR /&gt;:enable_secondary_connect (&lt;BR /&gt;:gateway (&lt;BR /&gt;:map (&lt;BR /&gt;:false (false)&lt;BR /&gt;:true (true)&lt;BR /&gt;:client_decide (client_decide)&lt;BR /&gt;)&lt;BR /&gt;:default (false)&lt;BR /&gt;)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have anyone manage to overcome this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 13 Nov 2023 13:26:45 GMT</pubDate>
    <dc:creator>Vladimir123</dc:creator>
    <dc:date>2023-11-13T13:26:45Z</dc:date>
    <item>
      <title>2 Sites with same VPN domain without MEP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Sites-with-same-VPN-domain-without-MEP/m-p/197810#M4394</link>
      <description>&lt;P&gt;Hello team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have primary VPN site for our VPN clients but we want some of them to use secondary.&lt;/P&gt;&lt;P&gt;Primary site and secondary site is managed by same SMS, they are connected over MPLS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Primary site is cluster with 5600 and secondary is open server, they all run on latest R81.20 with HF26.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried disabling MEP and Secondary Connect but primary site is showing problems. Ill need to remove/add vpn site everytime to work. First time VPN will connect, and second time will immediately drop.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have read this and pretty much i have same issue.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/Two-Gateways-Serving-the-Same-Encryption-Domain/td-p/178621" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/Two-Gateways-Serving-the-Same-Encryption-Domain/td-p/178621&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"trac_client_1.ttm" file edited on all GWs, example bellow is from Site1 GW.&amp;nbsp;&lt;/P&gt;&lt;P&gt;)&lt;BR /&gt;)&lt;BR /&gt;:mep_mode (&lt;BR /&gt;:gateway (&lt;BR /&gt;:map (&lt;BR /&gt;:dns_based (dns_based)&lt;BR /&gt;:first_to_respond (first_to_respond)&lt;BR /&gt;:primary_backup (primary_backup)&lt;BR /&gt;:load_sharing (load_sharing)&lt;BR /&gt;:client_decide (client_decide)&lt;BR /&gt;)&lt;BR /&gt;:default (primary_backup)&lt;BR /&gt;)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;)&lt;BR /&gt;)&lt;BR /&gt;:ips_of_gws_in_mep (&lt;BR /&gt;:gateway (&lt;BR /&gt;:default (Site1externalIP1&amp;amp;#Site1externalIP2&amp;amp;#)&lt;BR /&gt;)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;)&lt;BR /&gt;)&lt;BR /&gt;:automatic_mep_topology (&lt;BR /&gt;:gateway (&lt;BR /&gt;:map (&lt;BR /&gt;:false (false)&lt;BR /&gt;:true (true)&lt;BR /&gt;:client_decide (false)&lt;BR /&gt;)&lt;BR /&gt;:default (false)&lt;BR /&gt;)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;)&lt;BR /&gt;)&lt;BR /&gt;:enable_secondary_connect (&lt;BR /&gt;:gateway (&lt;BR /&gt;:map (&lt;BR /&gt;:false (false)&lt;BR /&gt;:true (true)&lt;BR /&gt;:client_decide (client_decide)&lt;BR /&gt;)&lt;BR /&gt;:default (false)&lt;BR /&gt;)&lt;BR /&gt;)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have anyone manage to overcome this problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 13:26:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Sites-with-same-VPN-domain-without-MEP/m-p/197810#M4394</guid>
      <dc:creator>Vladimir123</dc:creator>
      <dc:date>2023-11-13T13:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Sites with same VPN domain without MEP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Sites-with-same-VPN-domain-without-MEP/m-p/197831#M4395</link>
      <description>&lt;P&gt;You should not disable MEP, since both GWs have the same VPN domain. Use manual selection of the GW to connect, that's it, or Primary/backup option, if you want it to be automatic.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No need to edit ttm files.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 14:55:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Sites-with-same-VPN-domain-without-MEP/m-p/197831#M4395</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-11-13T14:55:19Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Sites with same VPN domain without MEP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Sites-with-same-VPN-domain-without-MEP/m-p/197969#M4396</link>
      <description>&lt;P&gt;Hey Val,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enabled MEP in global/advanced configuration&amp;nbsp;&lt;/P&gt;&lt;P&gt;Enabled manual MEP in client_1.ttm file on Site1 cluster GWs and Site2 GW&amp;nbsp;&lt;/P&gt;&lt;P&gt;- automatic_map_topology set to false&amp;nbsp;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;ips_of_gws_in_mep set to external IPs of each GWs&lt;/P&gt;&lt;P&gt;-&amp;nbsp;mep_mode set to client_decide&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got same result. First time would connect to Site1 but rest of connection&amp;nbsp;&lt;SPAN&gt;attempts&amp;nbsp;&lt;/SPAN&gt;will fail imidiattely.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 07:55:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Sites-with-same-VPN-domain-without-MEP/m-p/197969#M4396</guid>
      <dc:creator>Vladimir123</dc:creator>
      <dc:date>2023-11-15T07:55:54Z</dc:date>
    </item>
    <item>
      <title>Re: 2 Sites with same VPN domain without MEP</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Sites-with-same-VPN-domain-without-MEP/m-p/197973#M4397</link>
      <description>&lt;P&gt;I suggest you open a TAC request for that. This normally should work out of the box without issues.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 08:02:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2-Sites-with-same-VPN-domain-without-MEP/m-p/197973#M4397</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-11-15T08:02:37Z</dc:date>
    </item>
  </channel>
</rss>

