Hi All,
I have a single VPN communities and wish to connect to Azure with primary and backup setup and route to other country via Azure.
Each country will have 2 IPsec towards Azure.
Checkpoint GW 1 --> Azure_Primary
Checkpoint GW 1 --> Azure_Backup
However, we configure route-based VPN (Gateway to Gateway) so that we have group with exclusion configure in MESH topology. However, since a single gateway and connect to Azure 2 peers, we can't have the same encryption domain as it will causes overlapping issue.
But the design are meant to have redundancy between each others, hence the Azure encryption domain are meant to be the same.
When a IPsec flap, we will have some issue towards certain IP range.
We found sk164355, is this a correct way to implement it ?