- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi ! I have problem with VPN tunnel in a VSX environment, I would like to build two VPN tunnel to the same remote peer-adress from two different VS, is that supported ?
My gateway-server is on 77.30 and the management-server on 80.10.
It look good from the beginning and booth of the tunnel rise, but after a while one of them goes down and
get "authentication failure" when the remote side tried to connect.
The remote peer that I would like to peer with is located on a Juniper, Junos firewall.
Thank you for some help.
/Yngve
Do your VS' have unique public IPs assigned to their external interfaces or are they behind common VSwitch or external router being NATed to the same public IP?
Booth of the VS have unique ip-addresses and are connected with a common VSwitch to Internet.
Some more information,
we use the same "Interoperable Device" object as gateway in two different VPN community type meshed and we don't use Multi domain management. Hopefully I describe the setup on this case. I have not yet tried
this setup to other vendors than Juniper, I will try to use a Cisco ASA but it looks that it should be some problem
in my CP environment.
Are the 2 tunnels built in 1 community or in the same?
I would build 1 star community with the remote site as a center and set VPN routing to from satelite to center only.
This way you have 1 PSK for both tunnels, I have a customer running this type of setup with some different appliances to Amazon (although they are not VS's).
We have 2 separate community, because there are different company in each VS and they should not be dependent to each other. But maybe I can build this as one community and deny traffic between the two satellite.
But does any know if my setup would bee possible, we are going to use MDM in a feature and does that change any in this case?
This is why I said, build a Star with the REMOTE gateway as the CENTER, you can disallow traffic from one to the other VS.

But, when I build a start community I have only one of my VS that are the center gateway and if that one goes down the
traffic from the satellite to the other VS does not work.
A picture for no misunderstanding.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 10 | |
| 9 | |
| 9 | |
| 5 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY