I have been tasked with creating two VPN connections to a new vendor, a backup and a primary. Each has a different peer IP but the catch is the encryption domain will be the same on both.
I am not clear yet if both VPN connections will be up all of the time or not (I don't know if they are using probing, or DPD, or something that will keep phase 1 and 2 up).
To meet this requirement is it valid for me to configure one VPN star community and have both of the vendor's Satellite Gateways in the community like in the screen shot? Everything except the peer IP's is the same, encryption, lifetimes, etc.
The production traffic traversing the VPN will always be initiated from the remote end.
Will Check Point be able to route through the appropriate VPN by knowing which one received the traffic?
Thank you in advance.