Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
jure
Explorer
Jump to solution

Two interoperable devices with same encryption domain for VPN failover?

Hi all,

I need to build a redundant Site-to-Site VPN between a Check Point ClusterXL running R81.10 and a Huawei Gateway with two WAN interfaces. The Huawei device has two public WAN IPs, but both links use the same encryption domain. WAN2 should only be used as a backup/failover link, no load balancing is required.

Currently a domain-based VPN with a single WAN link is already working without issues.

I would like to know what is considered best practice on the Check Point side for implementing WAN redundancy in this kind of setup. Is it supported to create two interoperable devices (one per Huawei WAN IP), use the same encryption domain on both objects, and add both as satellite gateways into the same VPN community? 

Or is it strictly recommended to use Route-Based VPN in this setup?

Thanks in advance!

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

This SK suggests you can do it without resorting to Route-Based VPN: https://support.checkpoint.com/results/sk/sk164355 

View solution in original post

3 Replies
PhoneBoy
Admin
Admin

This SK suggests you can do it without resorting to Route-Based VPN: https://support.checkpoint.com/results/sk/sk164355 

jure
Explorer

thanks for sharing this SK. I looked into Check Points documentation on MEP (Multiple Entry Point (MEP) VPNs). According to the documentation, implicit MEP is supported in scenarios where fully or partially overlapping encryption domains exist, or where Primary/Backup Security Gateways are configured.

Do you recommend using explicit MEP in this scenario, or would implicit MEP do the job as well?

0 Kudos
PhoneBoy
Admin
Admin

Assuming you meet the criteria for Explicit MEP, I see no reason not to use it.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events