Hello, friends.
I'm trying to set up a Route-Based IPsec VPN between Check Point and FortiGate using Enhanced Link Selection and BGP.
Both sides have 2 ISPs. On the Check Point side, I've configured Enhanced Link Selection as Active/Active and added both peer IPs to the Interoperable Device -> Topology.
Community Settings
Check Point Enhanced Link Selection
3rd Party Enhanced Link Selection
Interoperable Device Topology
The issue is that this setup only provides one VTI. While Check Point seems to "float" this VTI between the two ISPs, FortiGate requires a dedicated VTI (Phase 1) for each tunnel to work properly with BGP.
I found a similar discussion here (IPsec Enhanced Mode tunnel redundancy), but it focuses on Domain-Based VPN. I’ve already tested Domain-Based, but the failover is too slow (over a minute) and unreliable for our needs.
I previously tried the "old school" method of creating two separate Interoperable Devices, but it was unstable and seems to defeat the purpose of Enhanced Link Selection.
Is there a way to achieve fast BGP convergence using VTIs while still leveraging Enhanced Link Selection, or am I hitting a limitation of how CP interacts with 3rd-party VTIs?
Thanks in advance.
Best Regards,
Hugo Thebas