<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Site2Site DR setup with ASA in Training and Certification</title>
    <link>https://community.checkpoint.com/t5/Training-and-Certification/Site2Site-DR-setup-with-ASA/m-p/24014#M441</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Failover DR related Question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have an established Site2Site VPN connectivity between ASA and checkpoint as in pic (Firewall 1 and Firewall 2)&lt;/P&gt;&lt;P&gt;we want to have DR tunnel Site2Site VPN (Firewall 1 and Firewall 3)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem is that Site 2 and Site 3 has a layer 2 auto failover using NSX VMware technology and encryption domain is same for these tunnels.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best way to achieve this auto failover in case of Firewall 2 site is destroyed..?&lt;/P&gt;&lt;P&gt;layer 2 failover will only happen if firewall 2 is unresponsive.. or in case a disaster. meaning the failover of Layer 2 IP's will happen to firewall 3. Can i achieve this with same encryption domain IP's? and will ASA be smart enough or a change will be needed there as well.. Open to ideas if someone has worked in a situation like this or if there is an SK which can guide me ..?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 04 Sep 2018 01:34:57 GMT</pubDate>
    <dc:creator>Upraj_Singh</dc:creator>
    <dc:date>2018-09-04T01:34:57Z</dc:date>
    <item>
      <title>Site2Site DR setup with ASA</title>
      <link>https://community.checkpoint.com/t5/Training-and-Certification/Site2Site-DR-setup-with-ASA/m-p/24014#M441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Failover DR related Question.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have an established Site2Site VPN connectivity between ASA and checkpoint as in pic (Firewall 1 and Firewall 2)&lt;/P&gt;&lt;P&gt;we want to have DR tunnel Site2Site VPN (Firewall 1 and Firewall 3)&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem is that Site 2 and Site 3 has a layer 2 auto failover using NSX VMware technology and encryption domain is same for these tunnels.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the best way to achieve this auto failover in case of Firewall 2 site is destroyed..?&lt;/P&gt;&lt;P&gt;layer 2 failover will only happen if firewall 2 is unresponsive.. or in case a disaster. meaning the failover of Layer 2 IP's will happen to firewall 3. Can i achieve this with same encryption domain IP's? and will ASA be smart enough or a change will be needed there as well.. Open to ideas if someone has worked in a situation like this or if there is an SK which can guide me ..?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Sep 2018 01:34:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Training-and-Certification/Site2Site-DR-setup-with-ASA/m-p/24014#M441</guid>
      <dc:creator>Upraj_Singh</dc:creator>
      <dc:date>2018-09-04T01:34:57Z</dc:date>
    </item>
  </channel>
</rss>

