- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
When the Agents Attack
A Live Look at Agentic Exposure Validation
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hi Mates,
After configuring two numbered VTIs with static routes and different priorities, when the primary tunnel goes down, traffic does not fail over to the backup tunnel. Any idea please?
We solved it by repeating the process (recreating the VTI), and we also tested the failover successfully. Everything is now working as expected based on this SK:
https://support.checkpoint.com/results/sk/sk156812
Are you using DPD and how are the return routes configured?
I'm using permanent tunnel on the community:
set static-route x.x.x.x/24 nexthop gateway address 169.254.x.x priority 1 on
set static-route x.x.x.x/24 nexthop gateway address 169.254.x.x priority 2 on
set static-route x.x.x.x/24 ping on
When the first tunnel is down, did you check, in bash, with the command ip route get <ip_of_a_remote_host> what route is used to reach the remote host?
Both remote hop (169.254.x.x) are pingable from the gateway?
My configuration looks something like this:
set static-route 10.x.x.x/24 nexthop gateway address 172.20.x.x priority 1 on
set static-route 10.x.x.x/24 nexthop gateway address 172.20.x.x monitored-ip 192.168.x.x on
set static-route 10.x.x.x/24 nexthop gateway address 172.20.x.x monitored-ip-option fail-any
set static-route 10.x.x.x/24 nexthop gateway logical vpnt10 priority 2 on
Make sure you have a monitored IP set for the primary so it knows when to use the backup.
Based on this sk https://support.checkpoint.com/results/sk/sk156812
The configuration reported by @RemoteUser should be consistent, eventually, It might be worth checking whether pings are allowed.
I wonder if this is really enough for failover, or if something else is still needed
As a first step, I would check if ping is ok, if yes, you can proceed with further checks, for example, by checking which route is used when the first vpn is down.
We solved it by repeating the process (recreating the VTI), and we also tested the failover successfully. Everything is now working as expected based on this SK:
https://support.checkpoint.com/results/sk/sk156812
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 9 | |
| 8 | |
| 8 | |
| 6 | |
| 6 | |
| 6 | |
| 5 | |
| 3 | |
| 3 | |
| 3 |
Wed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningWed 10 Jun 2026 @ 01:00 PM (EDT)
Deep Dive: When the Agents Attack: A Live Look at Agentic Exposure ValidationThu 11 Jun 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #8: Say Yes to AI Without Saying Yes to RiskFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY