Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
TINTIN8
Participant
Jump to solution

R82 Site to Site VPN with third party Router

Hi Checkpoint Gurus

I'm trying to set up a site-to-site VPN with a third-party GW (Router). In the new R82, it looks like there is a feature called "Enhanced link selection."

In my GW object, I've defined the External interface as Enhanced Link Selection. But realistically, we don't know how third-party devices are configured. All we do is exchange the security parameters with the given IP address and accept the interesting traffic.

The problem is that I cannot set up my VPN community in Enhanced mode without defining an Enhanced link selection on the third-party object. This doesn't make sense.

The error message says, "The VPN Community is configured to use "Enhanced Link Selection. "At least one VPN peer does not have configured interfaces. You must configure Enhanced Link Selection Interfaces in each VPN peer object."

Please refer to the attached pictures.

We cannot define interface details on third-party objects, and it's not practical to ask our vendors for this information.

Your help is much appreciated!!!

 

0 Kudos
2 Solutions

Accepted Solutions
the_rock
Legend
Legend

Please see attached.

Andy

View solution in original post

(1)
the_rock
Legend
Legend

@TINTIN8 Hopefully screenshots I sent are good enough, but if not, let me know.

Andy

View solution in original post

0 Kudos
(1)
8 Replies
the_rock
Legend
Legend

I did this in my R82 lab, will send you some screenshots tomorrow. Error is telling you that peer link selection is incorrect, thats why.

Andy

0 Kudos
TINTIN8
Participant

Thanks the_rock!!!

the_rock
Legend
Legend

Of course @TINTIN8 

0 Kudos
the_rock
Legend
Legend

Please see attached.

Andy

(1)
TINTIN8
Participant

Thank you soooo much!!! it worked!!!

the_rock
Legend
Legend

Glad we can help.

Andy

0 Kudos
PhoneBoy
Admin
Admin

For interoperable objects, the interface name doesn't have to match what the remote end actually uses.
You can use something generic like eth0.
The important thing is that interfaces are defined with the correct IP addresses.

the_rock
Legend
Legend

@TINTIN8 Hopefully screenshots I sent are good enough, but if not, let me know.

Andy

0 Kudos
(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 18 Mar 2025 @ 09:30 AM (EET)

    CheckMates Live Greece

    Tue 25 Mar 2025 @ 12:00 PM (MDT)

    Salt Lake City: CPX 2025 Recap

    Tue 08 Apr 2025 @ 12:00 PM (MDT)

    Denver: CPX 2025 Recap
    CheckMates Events