<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VTI unnumbered with 3rd party in Chinese 中文</title>
    <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50707#M484</link>
    <description>&lt;P&gt;在公有雲上要想想別的辦法了,傳統的clusterxl機制不再,改成用API的方式,所以時間會比以前長很多,這好像是沒有辦法的事。&lt;/P&gt;</description>
    <pubDate>Fri, 12 Apr 2019 09:02:35 GMT</pubDate>
    <dc:creator>Neville_Kuo</dc:creator>
    <dc:date>2019-04-12T09:02:35Z</dc:date>
    <item>
      <title>VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/47344#M463</link>
      <description>&lt;P&gt;實作 VTI unnumbered with 3rd party (FortiGate 60C, Juniper SSG5)，以下是簡略的 memo 留存。(只記錄我方重點步驟，其餘留default，或二端匹配之VPN設定)&lt;/P&gt;&lt;P&gt;VTI unnumbered&lt;BR /&gt;1. GaIA - add vpn tunnel 1 type unnumbered local peer peergwname dev eth0&lt;BR /&gt;2. GaIA - set static-route xx.xx.xx.xx/yy nexthop gateway logical vpnt1 on&lt;BR /&gt;3. SmartConsole - Create a empty Group object. (I.E. VPN_Empty)&lt;BR /&gt;4. SmartConsole - Create a Interoperable Devices - IPv4 Address&lt;BR /&gt;5. SmartConsole - Modify Interoperable Devices - Topology - VPN Domain - Manually defined - VPN_Empty&lt;BR /&gt;5. SmartConsole - Create a community with two firewall peers.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 05:56:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/47344#M463</guid>
      <dc:creator>George_Liu</dc:creator>
      <dc:date>2019-03-18T05:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/47357#M464</link>
      <description>&lt;P&gt;You found detail&amp;nbsp; informations here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.10/WebAdminGuides/EN/CP_R80.10_SitetoSiteVPN_AdminGuide/html_frameset.htm" target="_self"&gt;Site to Site VPN Administration Guide R80.10&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 06:39:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/47357#M464</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-18T06:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/47358#M465</link>
      <description>Tip:&lt;BR /&gt;-use  IKEv1&lt;BR /&gt;-use same  ProxyID&lt;BR /&gt;- on ssg side:&lt;BR /&gt;   - add gateway&lt;BR /&gt;   - add VPN tunnel Interface &lt;BR /&gt;   - add route&lt;BR /&gt;   - add VPN role&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 18 Mar 2019 06:55:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/47358#M465</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-03-18T06:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/48367#M467</link>
      <description>&lt;P&gt;需注意corexl問題,在R77.30之前route based vpn不支援。&lt;/P&gt;</description>
      <pubDate>Sat, 23 Mar 2019 04:17:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/48367#M467</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-03-23T04:17:20Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/48409#M468</link>
      <description>&lt;P&gt;通过static route priority能做出来两条route based vpn是Active/Standby的效果吗？&lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2019 10:51:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/48409#M468</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2019-03-24T10:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/48416#M469</link>
      <description>&lt;P&gt;當然可以,還可以做route monitor,或者配合dynamic routing做出漂亮的流量工程。&lt;/P&gt;</description>
      <pubDate>Sun, 24 Mar 2019 12:56:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/48416#M469</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-03-24T12:56:17Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/48942#M470</link>
      <description>拜读过N大的Route-based vpn with OSPF.&lt;BR /&gt;最近在测试route-based vpn ,当中需要用到pbr，好像pbr没办法通过priority来切换。&lt;BR /&gt;还在测试中……</description>
      <pubDate>Thu, 28 Mar 2019 02:19:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/48942#M470</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2019-03-28T02:19:20Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/48947#M471</link>
      <description>&lt;P&gt;如果您的PBR的next hop是多個IP,那我們的經銷夥伴測試過了,看來是不行,CP的routing功能不強。&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 06:41:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/48947#M471</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-03-28T06:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/48954#M472</link>
      <description>嗯，我们有两条VPN Tunnel，想通过pbr中next hop优先级来做active/standby。&lt;BR /&gt;看样子只能用dynamic routing了？</description>
      <pubDate>Thu, 28 Mar 2019 07:05:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/48954#M472</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2019-03-28T07:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/49015#M474</link>
      <description>&lt;P&gt;如果需求只是這樣,那您就更應該考慮用dynamic routing了,試試用簡單的RIP,兩個interface設定不同cost,就可以達到您要的效果了,在小範圍裡它算最好上手的routing protocol了,當然記得policy要allow RIP,如果用OSPF更好。&lt;/P&gt;&lt;P&gt;PBR對securexl有反效果,所以對效能也有不好影響,我個人不建議也不喜歡。&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2019 12:10:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/49015#M474</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-03-28T12:10:29Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50061#M479</link>
      <description>&lt;P&gt;unnumber vti 不支持 route ping monitor，最近測試發現的，現在準備試看看 vti number 能不能實現這個需求。&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2019 13:39:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50061#M479</guid>
      <dc:creator>George_Liu</dc:creator>
      <dc:date>2019-04-07T13:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50068#M480</link>
      <description>&lt;P&gt;喬治哥:&lt;/P&gt;&lt;P&gt;基本上您的需求把vti介面設IP就對了,我們有個客戶跑了3條route based vpn,都有做route monitoring。&lt;/P&gt;&lt;P&gt;這個情況很正常,因為unnumber其實是和實體介面"借"了一個IP過來,如果要做route monitoring,對底層的OS而言,它會不知道要帶實體介面或者vti去ping next hop的,因為IP都是同一個。&lt;/P&gt;&lt;P&gt;假設Route based vpn架構單純(只有兩個點),懶得幫vti介面想IP,卻又要讓某些需要NAT traversal的應用(如IPsec或VOIP)封包通過的話,直接用unnumber很適合,因為您的目的只是為了有IP可以去轉換而已,但是如果像我們常會遇到Dynamic routing, route monitor,或vti有多個next hop的需求時, unnumber是行不通的。&lt;/P&gt;&lt;P&gt;所以後來我都不用unnumber interface了,即使架構簡單。&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 07 Apr 2019 15:03:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50068#M480</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-04-07T15:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50371#M481</link>
      <description>&lt;P&gt;受益了。&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 03:34:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50371#M481</guid>
      <dc:creator>George_Liu</dc:creator>
      <dc:date>2019-04-10T03:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50372#M482</link>
      <description>&lt;P&gt;To Dawei&lt;/P&gt;&lt;P&gt;實作 vti number + static route ping monitor + static route priority 可達到您要的 active /standby 線路需求。&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 03:36:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50372#M482</guid>
      <dc:creator>George_Liu</dc:creator>
      <dc:date>2019-04-10T03:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50692#M483</link>
      <description>乔治哥，&lt;BR /&gt;&lt;BR /&gt;确实static route应该是可以的。&lt;BR /&gt;后续我们使用了N大建议的OSPF，但是我这边是在AWS上测试，发现一个很奇怪的现象：&lt;BR /&gt;由于我是通过Route-based VPN建立的OSPF，在AWS上ClusterXL切换最长可能要40+s，正好大于了OSPF的dead timer.&lt;BR /&gt;&lt;BR /&gt;所以，几乎每次都会切到另外一个neighbor，再切回来。&lt;BR /&gt;而且我们发现，如果过了Dead Time,ClusterXL切换还没完成的话，有很大概率会发生主线路的route-based VPN不通的情况。&lt;BR /&gt;&lt;BR /&gt;大概需要30分钟，甚至更长，才能恢复。&lt;BR /&gt;这时由于priority和cost的设置，路由会切回active线路。</description>
      <pubDate>Fri, 12 Apr 2019 05:23:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50692#M483</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2019-04-12T05:23:39Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50707#M484</link>
      <description>&lt;P&gt;在公有雲上要想想別的辦法了,傳統的clusterxl機制不再,改成用API的方式,所以時間會比以前長很多,這好像是沒有辦法的事。&lt;/P&gt;</description>
      <pubDate>Fri, 12 Apr 2019 09:02:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50707#M484</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-04-12T09:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50830#M485</link>
      <description>&lt;P&gt;对的。API的方式，没法改变。&lt;BR /&gt;不过，我说的30分钟不是clusterXL failover的时间，正常failover的时间在40-60s左右。&lt;BR /&gt;&lt;BR /&gt;但是VPN这个问题，我现在只能开SR请TAC帮忙了。不知道能不能解决。&lt;/P&gt;</description>
      <pubDate>Sat, 13 Apr 2019 15:43:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/50830#M485</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2019-04-13T15:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/53258#M499</link>
      <description>&lt;P&gt;在R80.30的新功能可以試試,我還沒玩過:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Advanced Routing&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Multihop Ping and Multiple ISPs in Policy-Based Routing&lt;/LI&gt;&lt;LI&gt;Multihop Ping in Static Routes&lt;/LI&gt;&lt;LI&gt;BFD in Static Routes&lt;/LI&gt;&lt;LI&gt;VSX VSID in Netflow&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;但是Public cloud的R80.30不知道釋出了沒有。&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2019 02:12:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/53258#M499</guid>
      <dc:creator>Neville_Kuo</dc:creator>
      <dc:date>2019-05-13T02:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/53267#M500</link>
      <description>上周部署AWS暂时还没有R80.30。&lt;BR /&gt;之前的问题后面用了BGP来解决。但是后面发现AWS上，在HA切换后Route-based VPN会起不来，导致BGP路由学不到。&lt;BR /&gt;还在和TAC沟通中。</description>
      <pubDate>Mon, 13 May 2019 04:56:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/53267#M500</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2019-05-13T04:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: VTI unnumbered with 3rd party</title>
      <link>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/53479#M501</link>
      <description>今天突然发现sk104418中提到：&lt;BR /&gt;Route Based VPN (with VTI) is not supported over cluster solution.&lt;BR /&gt;&lt;BR /&gt;……</description>
      <pubDate>Wed, 15 May 2019 07:03:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Chinese-%E4%B8%AD%E6%96%87/VTI-unnumbered-with-3rd-party/m-p/53479#M501</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2019-05-15T07:03:00Z</dc:date>
    </item>
  </channel>
</rss>

