Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
SriNarasimha005
Collaborator
Jump to solution

ELS or BGP for Traffic forwarding and Failover in Route based VPN?

Hi 

I'd like to configure a Route-based VPN between the Checkpoint firewall to the Peer Interoperable device- Cisco Router for a INTERNAL traffic.

Although the Peer device is one, there would be 2 separate links with different set of IP address provided by different ISP and to advertise the routes, we're planning to use BGP.

Should I have to use Enhanced Link Selection (ELS) or rely on BGP for link preference and failover (using Metrics) in this scenario? Can someone please help?

Thank you.

 

1 Solution

Accepted Solutions
israelfds95
MVP Diamond
MVP Diamond

From my understanding, these two features serve different purposes and are not mutually exclusive.

Enhanced Link Selection (ELS) is responsible for selecting the local interface used to establish the VPN tunnel (IKE Phase 1). It improves interoperability with third-party VPN devices by providing redundancy and load sharing without relying on Check Point's proprietary VPN Link Selection (RDP) protocol.

BGP, on the other hand, is responsible for advertising and selecting routes once the VPN tunnels are established. 

So, if you're deploying a route-based VPN with BGP,  ELS can still be used to determine which local interface is used to establish the VPN tunnels, but it does not replace the routing decisions made by BGP or any other routing mechanism you choose to use for the VPN

I also recommend reviewing:

  • R82 Site-to-Site VPN Administration GuideOverview of Enhanced Link Selection and the Enhanced Link Selection Limitations section.
  • R82 Gaia Advanced Routing Administration Guide for the BGP design and routing behavior.

View solution in original post

1 Reply
israelfds95
MVP Diamond
MVP Diamond

From my understanding, these two features serve different purposes and are not mutually exclusive.

Enhanced Link Selection (ELS) is responsible for selecting the local interface used to establish the VPN tunnel (IKE Phase 1). It improves interoperability with third-party VPN devices by providing redundancy and load sharing without relying on Check Point's proprietary VPN Link Selection (RDP) protocol.

BGP, on the other hand, is responsible for advertising and selecting routes once the VPN tunnels are established. 

So, if you're deploying a route-based VPN with BGP,  ELS can still be used to determine which local interface is used to establish the VPN tunnels, but it does not replace the routing decisions made by BGP or any other routing mechanism you choose to use for the VPN

I also recommend reviewing:

  • R82 Site-to-Site VPN Administration GuideOverview of Enhanced Link Selection and the Enhanced Link Selection Limitations section.
  • R82 Gaia Advanced Routing Administration Guide for the BGP design and routing behavior.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events