- CheckMates
- :
- Products
- :
- General Topics
- :
- Multiple Satelitte Gateways - VPN Setup
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Multiple Satelitte Gateways - VPN Setup
Hi all,
Could anyone help me out at all? Even if there's a guide I've missed, or a CheckMates post already on this (I did search, but only found some questions vaguely similar) that'd be great.
I am wanting to setup 2 VPN Tunnels/1 Community
A Side (Me) - Check Point Sec GW R80.10
B Side - 2 x AWS Cloud GWs
We've had "Tunnel 1" setup already, and when we put traffic through it, it did work. So that should be fine.
Struggling with how to setup "Tunnel 2".
The only differences between Tunnel 1 and Tunnel 2:
IPs are not the IPs in use, just examples which reflect the same scenario -
T1:
Outside Customer GW: 28.226.247.191
Outside Virtual GW: 28.200.211.101
Inside Customer GW: 159.254.87.40/30
Inside Virtual GW: 159.254.87.39/30
Next Hop: 159.254.87.39
T2:
Outside Customer GW: 28.226.147.191
Outside Virtual GW: 28.203.110.6
Inside Customer GW: 159.254.184.96/30
Inside Virtual GW: 159.254.184.95/30
Next Hop: 159.254.184.95
So a Star Community?
Center - My Cluster object
Satelittes - Both Interoperable devices?
Tunnel - Per subnet pair or Per gateway pair?
VPN Routing - Center only?
In the Interoperable device -
IP: Outside Virtual Private Gateway IP?
Topology: Manually defined ENC domain (group to be empty?)
I appreciate any input in advance.
Thanks,
Ben
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Uh, that changes things a bit. Look here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Maarten,
Sorry yes, the 2nd tunnel is to be used for redundancy.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Uh, that changes things a bit. Look here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
it depends on your needs. You can either do two communities, or a single star with your physical cluster in the center and some optional VPN routing between satellites. Center only means traffic between satellites will not be passing through.
Use per par of GWs, as recommended here: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
