Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RemoteUser
Advisor

S2S With Cato

Hi Mates,

I have a question regarding the setup of a Site-to-Site VPN between a Check Point cluster and two Cato peers with redundancy.

What is the best way to configure this scenario to ensure proper redundancy and failover between the two peers? Thanks

0 Kudos
8 Replies
simonemantovani
MVP Silver
MVP Silver

Hello

the best solution is to use route based vpn with dynamic routing protocol like BGP.

0 Kudos
RemoteUser
Advisor

Hi Simone,

Is it also possible to achieve this using MEP, with the center gateways acting as the peer gateways? And in satellite gateways my checkpoint cluster?

0 Kudos
simonemantovani
MVP Silver
MVP Silver

MEP is only available between Check Point gateways.

I'm pretty sure that Cato support VPN route-based with BGP (or eventually static routing); I found a documentation page from Cato official site related to VPN between AWS gateway with redundancy.

Usually if you need redundancy, the best solution (adopted also by cloud provider, Harmony SASE, etc.) is route based vpn with routing protocol.

0 Kudos
RemoteUser
Advisor

hi simone,
so i need to create VTI for this right?

0 Kudos
simonemantovani
MVP Silver
MVP Silver

Yes, you should create 2 VTIs numbered

0 Kudos
RemoteUser
Advisor

We also need to configure two networks between the Check Point cluster and the remote peers (e.g., 169.254.x.x), one for each tunnel, and then set up the routing accordingly, right?

0 Kudos
simonemantovani
MVP Silver
MVP Silver

Yes you're right.

Have you already configured a route based vpn in the past?

0 Kudos
RemoteUser
Advisor

Yes, with AWS the usually provide a file with all the steps to follow, while in this case we don’t have it, which is why I’m asking.

At this point, we also need to inform the other side that we are going to set up a VTI tunnel, since they will need to configure the corresponding networks (169.254.x.x) accordingly as well. Am I right?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 07 May 2026 @ 01:30 PM (AEST)

    CheckMates Live Sydney

    Tue 02 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Aarhus

    Wed 03 Jun 2026 @ 09:00 AM (CEST)

    CheckMates Live Denmark - Copenhagen
    CheckMates Events