Hi Checkmates,
I found some topics in this Community concerning VTIs, but all scenarios seem different to mine so I'm asking you guys for your insights.
We have 2 CheckPoint clusters, both centrally managed in the same SMS. One is Openserver R77.30, the other is a 1450 cluster R77.20.8x. In a normal situation, these sites communicate via MPLS. As a backup connection, we are required to configure an IPSEC site-to-site tunnel. To make failover (from MPLS to S2S) possible, I'm configuring VTI interfaces with routes with a higher metric.
I found some SKs about this (sk113735) and read "Configuring Numbered VTIs" in the Admin Guide but.
The Admin Guide describes how you create 1 VTI tunnel pair between the cluster and one gateway:
But we need this:
1) VTI pair between memberA1 and memberB1
2) VTI pair between memberA1 and memberB2
3) VTI pair between memberA2 and memberB1
4) VTI pair between memberA2 and memberB2
But this creates two tunnels, making it impossible to create working routing.
Or am I missing something?