Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Blason_R
Leader
Leader
Jump to solution

Do I need to create manually Site-Site tunnels with firewalls before SDWAN

Hi Team,

 

Wondering if I need to configure Site-Site VPN on management server through smart console before I configure the SDWAN beween firewalls? Will that be Mesh topology?

Or SDWAN agent will configure the tunnels on its own?

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
1 Solution

Accepted Solutions
AmirArama
Employee
Employee

Currently you can have SD-WAN Overlay only between firewalls managed by the same Management server (on the roadmap in between different Domains in MDM server).

the authentication will be based on certificate as today. we don't change that.

if there is already VPN tunnel between those gateways, once you enable SD-WAN on those peers (both sides), the tunnels will be changed from link selection to tunnel per interface by SD-WAN.

if everything is configured properly in advance, the switch should be quick.

View solution in original post

0 Kudos
3 Replies
AmirArama
Employee
Employee

Hi,
we are based on the management server for VPN Configuration.
VPN Configuration still managed in the Smart Console. once there is VPN between peers, the SD-WAN build tunnel per interface between the peers (replace the GW OBJECT > IPSEC VPN > Link selection), and will apply the SD-WAN overlay on top of it.

the community can be either mesh or star.

you can learn more here:

https://support.checkpoint.com/results/sk/sk180605

feel free to ask more questions.

0 Kudos
Blason_R
Leader
Leader

And what if the tunnel is already there between peer? Plus what would happen if the same management server is managing those firewalls? In that case it will be a certificate based IPSEC vpn. Will that work seamlessly?

Thanks and Regards,
Blason R
CCSA,CCSE,CCCS
0 Kudos
AmirArama
Employee
Employee

Currently you can have SD-WAN Overlay only between firewalls managed by the same Management server (on the roadmap in between different Domains in MDM server).

the authentication will be based on certificate as today. we don't change that.

if there is already VPN tunnel between those gateways, once you enable SD-WAN on those peers (both sides), the tunnels will be changed from link selection to tunnel per interface by SD-WAN.

if everything is configured properly in advance, the switch should be quick.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events