Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
zsszlama
Contributor
Contributor

Mesh topology with failover

Hi All,

We have the following situation: the company has many Check Point Gateways in different countries they are connected in mesh topology. Every node has local breakout traffic, only private traffic is going through the S2S tunnels.

Use case is when S2S connect fails between SiteA and SiteB then CP somehow detects this failure and routes traffic to a specific node (SiteC) and from SiteC the traffic goes to SiteB.


                                            Site B
                                          /           \
                                        /               \
                                   VPN            VPN
                                    /                       \
                            Site A ─────── Site C
                                             VPN

Normal flow: SiteA <-> SiteB
Failover flow: SiteA <-> SiteC <-> SiteB

 

Do you have any suggestion how this scenario is solvable with a CP solution or with some kind of configuration?

 

Any comments are welcome!

 

Thanks in advance!

Best regards,

Zsolt

0 Kudos
2 Replies
Bob_Zimmerman
MVP Gold
MVP Gold

The easiest way would probably be to use route-based VPNs with numbered VTIs, then running dynamic routing over the VTIs. All of the firewalls would have a consistent view of the whole topology. If a link fails, routing would reconverge and send traffic through the best remaining path.

Moving from domain-based VPNs to route-based is a little weird. You still use the VPN community object to specify the cryptographic parameters of the VPN, but you have to break the normal encryption domain logic and let routing send traffic "out" the interface for a given VPN. The most common way to break this logic is to set the encryption domain of most or all of the firewalls to an empty group.

With the empty encryption domains, the traffic no longer counts as going across the VPN for rule purposes, so it won't match rules which specify the VPN community. Use the "Any Traffic" special value instead.

0 Kudos
zsszlama
Contributor
Contributor

That was our first thought too.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events