<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple VTI tunnels with BGP to third party from Quantum Spark - no SmartConsole or Communities in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Multiple-VTI-tunnels-with-BGP-to-third-party-from-Quantum-Spark/m-p/228904#M11543</link>
    <description>&lt;P&gt;Was able to engage Check Point support. It turns out that in our case to use the redundant tunnels we need to use MEP, which can be used with DPD instead of RDP (Check Point proprietary), however, to use MEP with our device requires centrally managed system like SmartConsole.&amp;nbsp; We are going to work with the third party to just use a single tunnel. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Oct 2024 20:14:33 GMT</pubDate>
    <dc:creator>ITSOU-SVC</dc:creator>
    <dc:date>2024-10-03T20:14:33Z</dc:date>
    <item>
      <title>Multiple VTI tunnels with BGP to third party from Quantum Spark - no SmartConsole or Communities</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Multiple-VTI-tunnels-with-BGP-to-third-party-from-Quantum-Spark/m-p/228250#M11511</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Checkpoint Noob here.&amp;nbsp; Have been tasked with configuring a Spark 1570 running&amp;nbsp;&lt;SPAN&gt;R81.10.10 - Build 945.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Requires:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Third party has 2 IPs so we need two tunnels.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;BGP required, therefore VTI required.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I do not have access to SmartConsole (that I know of) or Communities (that I know of - is that an add-on product?)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I feel like the setup is going to be very similar to this:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk108958?source=sf&amp;amp;permanentid=baa13175f30b7728dd338ab071c94c441771f2ad18ac54cd5999e5a385f5&amp;amp;sysurihash=h4Kx7CBdPwA8jM4n&amp;amp;responseid=205b8988-14ad-43b9-b0a0-26efa6441ab0&amp;amp;documentposition=0" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk108958?source=sf&amp;amp;permanentid=baa13175f30b7728dd338ab071c94c441771f2ad18ac54cd5999e5a385f5&amp;amp;sysurihash=h4Kx7CBdPwA8jM4n&amp;amp;responseid=205b8988-14ad-43b9-b0a0-26efa6441ab0&amp;amp;documentposition=0&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I used the above guide to setup the tunnels successfully in Gaia but I don't have access to the SmartConsole to configure the Interoperable device (is not a object type in Gaia GUI).&amp;nbsp; I created a normal host object instead - don't know if that's going to work.&lt;/P&gt;&lt;P&gt;I don't have Communities apparently with the license for this device so I cannot setup the communities part. Can that portion be setup using Gaia command line?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I going to have to figure out how to add a license to use Communities?&amp;nbsp; Feeling very ignorant at the moment.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Sep 2024 15:42:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Multiple-VTI-tunnels-with-BGP-to-third-party-from-Quantum-Spark/m-p/228250#M11511</guid>
      <dc:creator>ITSOU-SVC</dc:creator>
      <dc:date>2024-09-27T15:42:43Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple VTI tunnels with BGP to third party from Quantum Spark - no SmartConsole or Communities</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Multiple-VTI-tunnels-with-BGP-to-third-party-from-Quantum-Spark/m-p/228417#M11512</link>
      <description>&lt;P&gt;You use a loclly managed Spark 1570 running R81.10.10, so you have no SmartConsole and only Embedded GAiA.&lt;/P&gt;
&lt;P&gt;Documentation:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/SMB_R81.10.X/RN/EN/Default.htm" target="_blank" rel="noopener"&gt;Quantum Spark 1500, 1600, 1800, 1900, and 2000 Appliance Series R81.10.X Release Notes&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Default.htm" target="_blank" rel="noopener"&gt;Quantum Spark 1500, 1600, 1800, 1900, and 2000 Appliance Series R81.10.X Locally Managed Administration Guide (English)&lt;/A&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Better look here for VPN with AWS:&amp;nbsp; &lt;A href="https://support.checkpoint.com/results/sk/sk111733" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk111733: How to configure Site-to-Site VPN between &lt;STRONG&gt;Amazon&lt;/STRONG&gt; &lt;STRONG&gt;Web&lt;/STRONG&gt; &lt;STRONG&gt;Services&lt;/STRONG&gt; and locally managed SMB appliance&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Besides: Can we move this post to Spark/SMB, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt; , &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt; ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 07:36:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Multiple-VTI-tunnels-with-BGP-to-third-party-from-Quantum-Spark/m-p/228417#M11512</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-09-30T07:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple VTI tunnels with BGP to third party from Quantum Spark - no SmartConsole or Communities</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Multiple-VTI-tunnels-with-BGP-to-third-party-from-Quantum-Spark/m-p/228479#M11524</link>
      <description>&lt;P&gt;VPN Communities and Interoperable Objects are only relevant when managed with a Smart-1, which is not the case for a locally managed device.&lt;BR /&gt;You can set up VTIs in Device &amp;gt; Network &amp;gt; Local Network &amp;gt; New &amp;gt; VPN Tunnel (VTIs).&lt;BR /&gt;You can set up the peer in VPN &amp;gt; Site to Site &amp;gt; VPN Sites.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 14:11:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Multiple-VTI-tunnels-with-BGP-to-third-party-from-Quantum-Spark/m-p/228479#M11524</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-30T14:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple VTI tunnels with BGP to third party from Quantum Spark - no SmartConsole or Communities</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Multiple-VTI-tunnels-with-BGP-to-third-party-from-Quantum-Spark/m-p/228904#M11543</link>
      <description>&lt;P&gt;Was able to engage Check Point support. It turns out that in our case to use the redundant tunnels we need to use MEP, which can be used with DPD instead of RDP (Check Point proprietary), however, to use MEP with our device requires centrally managed system like SmartConsole.&amp;nbsp; We are going to work with the third party to just use a single tunnel. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2024 20:14:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Multiple-VTI-tunnels-with-BGP-to-third-party-from-Quantum-Spark/m-p/228904#M11543</guid>
      <dc:creator>ITSOU-SVC</dc:creator>
      <dc:date>2024-10-03T20:14:33Z</dc:date>
    </item>
  </channel>
</rss>

