- CheckMates
- :
- Products
- :
- General Topics
- :
- Redundant VPN with Third Party
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Redundant VPN with Third Party
Hello folks,
I am not able to figure out how to create a redundant site to site VPN tunnel... I tried a few different options, no luck so far.
Our client have two ISPs connected to the same firewall (3rd party). On my side it will be one endpoint.
I am looking for an instant (or almost instant) failover in case there is an issue with any of client's internet circuits.
From your experience, what will be the best way to accomplish it?
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You need to configure MEP.
See: https://support.checkpoint.com/results/sk/sk164355
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you! How good it's working with 3rd party?
At this point I don't know what will be the client's firewall vendor.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Most of the interoperability issues that occur with third-party VPN gateways occur with getting the VPN established.
The MEP piece is pretty straightforward.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks!
So in my case I'm going to configure two remote client's firewalls as center gateways and my gateway as satellite, right?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That sounds correct.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
btw, will I see the same source IP, if the traffic is coming over the primary or secondary tunnel?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Keep in mind, MEP means you have multiple center gateways, so should not matter what 3rd party fw is.
Andy
