- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hello, I want to create a site-to-site VPN between two Check Point firewalls, both with public IPs. If both firewalls are managed by the same management console, is there another method to establish the connection, or can I do it as if they were two independent Check Points? What would be the best method to create a site-to-site VPN in this case?
If they are managed by the same Security Management Server it is as simple as adding them them to a VPN Community (and a couple of other steps...)
The main difference between a Meshed and a Star VPN Community lies in their topology and the way VPN tunnels are established:
Meshed VPN Community:
Star VPN Community:
Seems like in your case you need a simple Meshed VPN Community. No need for a dedicated shared secret since they are part of the same community (Shared Secret would be needed if the Security Gateways are not managed by the same Security Management Server)
If they are managed by the same Security Management Server it is as simple as adding them them to a VPN Community (and a couple of other steps...)
Its pretty much what Tal sent.
Andy
When creating the VPN community, it would be set up as a star, and both security gateways would be added as center gateways without a shared secret?
The main difference between a Meshed and a Star VPN Community lies in their topology and the way VPN tunnels are established:
Meshed VPN Community:
Star VPN Community:
Seems like in your case you need a simple Meshed VPN Community. No need for a dedicated shared secret since they are part of the same community (Shared Secret would be needed if the Security Gateways are not managed by the same Security Management Server)
"Thank you for your explanation, it was very clear."
To add to an excellent explanation Tal provided, hope below is useful too.
Andy
Thank you very much for the explanation, it will be helpful.
No problem, glad we can help.
Andy
If its only 2 firewalls, I never found much difference, but as @Tal_Paz-Fridman indicated, those are main differences. You are correct, only if you indicate satellite gateway, then you need to enter shared secret, so just add both of them (if its 2) as center gateways.
Andy
 
					
				
				
			
		
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count | 
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 11 | |
| 11 | |
| 7 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | 
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 11:00 AM (EDT)
Tips and Tricks 2025 #15: Become a Threat Exposure Management Power User!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY