- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Mates!
Let me explain the scenario... We have a big customer that has a cloudguard cluster. This cluster is behind of an OCI (Oracle Cloud Infrastructure) . This OCI manage IPs from public to private and the gateway just see the private IPs.
My gateway interfaces is like this:
This customer has many ranges of public IPs, so that each peer partner will use one of these public IPs to establish the VPN tunnel.
My doubt is: How can I configure all these IPs on the CP side so that it can respond for all partners, each one with a different IP?
Normally, in the VPN link selection, we set an IP that will respond to all partners.
Is it supported on Check Point?
Any advice?
Thank you!
You can read all about Link Selection here: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Con...
A routing configuration would assume that the public IPs were available on the interface the traffic is routed out.
Since everything on your gateways is private IPs, this will most definitely not work since the gateway won’t know what the public IP is on that interface.
Can you directly specify what peer uses what IP for Link Selection? No.
It would have to be done with routing, which given this scenario, may not be an option.
Hello @PhoneBoy . How could I use routing to make this?
I try to search for any documentation to help me with this configuration, but I guess that I'm not searching for the right keywords.
Have any way to make this work?
You can read all about Link Selection here: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SitetoSiteVPN_AdminGuide/Con...
A routing configuration would assume that the public IPs were available on the interface the traffic is routed out.
Since everything on your gateways is private IPs, this will most definitely not work since the gateway won’t know what the public IP is on that interface.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 12 | |
| 10 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY